CVE Database
/

CVE-2021-24218

Back to search

CVE-2021-24218

Published: Apr 12, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3.0.4 were vulnerable to CSRF due to a lack of nonce protection. The settings in the saveFbeSettings function had no sanitization allowing for script tags to be saved.

VendorProductVersions

Unknown

Facebook for WordPress

affected
3.0.0 - < 3.0.0*
affected
3.0.4 - < 3.0.4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now