CVE-2021-25072
NextScripts: Social Networks Auto-Poster <= 4.3.24 - Arbitrary Post Deletion via Cross-Site Request Forgery
mediumCross-Site Request Forgery (CSRF)
6.5
CVSS Score
6.5
CVSS Score
medium
Severity
4.3.25
Patched in
750d
Time to patch
Description
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin delete arbitrary posts via a CSRF attack
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NAttack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
None
Confidentiality
High
Integrity
None
Availability
Technical Details
Affected versions
<4.3.25PublishedJanuary 3, 2022
Last updatedJanuary 22, 2024
Affected pluginsocial-networks-auto-poster-facebook-twitter-g
Source Code
WordPress.org SVNVulnerable v3.8.8
Patched
Patched version not available.
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.