CVE-2021-25010
Post Snippets <= 3.1.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting
criticalCross-Site Request Forgery (CSRF)
9.6
CVSS Score
9.6
CVSS Score
critical
Severity
3.1.4
Patched in
722d
Time to patch
Description
The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting issues
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HAttack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
High
Confidentiality
High
Integrity
High
Availability
Technical Details
Affected versions
<=3.1.3PublishedJanuary 31, 2022
Last updatedJanuary 22, 2024
Affected pluginpost-snippets
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.