Back to search
CVE-2021-24218
Published: Apr 12, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3.0.4 were vulnerable to CSRF due to a lack of nonce protection. The settings in the saveFbeSettings function had no sanitization allowing for script tags to be saved.
| Vendor | Product | Versions |
|---|---|---|
Unknown | Facebook for WordPress | affected 3.0.0 - < 3.0.0*affected 3.0.4 - < 3.0.4 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now