CVE Database
/

CVE-2021-25075

Back to search

CVE-2021-25075

Published: Feb 21, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings, or perform such attack via CSRF. Furthermore, due to the lack of escaping, this could lead to Stored Cross-Site Scripting issues

VendorProductVersions

Unknown

Duplicate Page or Post

affected
1.5.1 - < 1.5.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now