CVE Database
/

CVE-2021-24446

Back to search

CVE-2021-24446

Published: Feb 14, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make logged in admins change them and lead to Stored XSS issue as well due to the lack of sanitisation

VendorProductVersions

Unknown

Remove Footer Credit

affected
1.0.6 - < 1.0.6

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now