8.1
CVSSv3

CVE-2021-24500

Published: 09/08/2021 Updated: 25/10/2022
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

Several AJAX actions available in the Workreap WordPress theme prior to 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an malicious user to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting arbitrary objects on the target site.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

amentotech workreap