[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1EZbmZYCr4JtawkCszmKQE7w4wp6M7jYqdG27SyuZD4":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20},"CVE-2021-24230","patreon-wordpress-cross-site-request-forgery-3","Patreon WordPress \u003C= 1.6.9 - Cross-Site Request Forgery","The Patreon WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.9. If exploited, this bug can be used to overwrite the “wp_capabilities” meta, which contains the affected user account’s roles and privileges. Doing this would essentially lock them out of the site, blocking them from accessing paid content.  This makes it possible for unauthenticated attackers to make a logged in user overwrite or create arbitrary user metadata on the victim’s account once visited via forged request granted they can trick a site administrator into performing an action such as clicking on a link.","patreon-connect",null,"\u003C1.7.0","1.7.0","high",8.1,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:N\u002FI:H\u002FA:H","Cross-Site Request Forgery (CSRF)","2021-03-26 00:00:00","2024-01-22 19:56:02",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Ffbcd569d-f524-4012-add0-ba0afc19e47e?source=api-prod",1033]