CVE Database
/

CVE-2021-25106

Back to search

CVE-2021-25106

Published: Feb 7, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1 does not check for authorisation and has a flawed CSRF logic when saving its settings, allowing any authenticated users, such as subscriber, to update them. Furthermore, due to the lack of sanitisation and escaping, it could lead to Stored Cross-Site Scripting

VendorProductVersions

Unknown

Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages

affected
2.7.1 - < 2.7.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now