Unrated severityNVD Advisory· Published Nov 8, 2021· Updated Aug 3, 2024
wpDiscuz < 7.3.4 - Arbitrary Comment Addition/Edition/Deletion via CSRF
CVE-2021-24806
Description
The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers could also make logged in users post arbitrary comment.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- WordPress/wpDiscuz WordPress plugindescription
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/2746101e-e993-42b9-bd6f-dfd5544fa3femitrex_refsource_MISC
News mentions
0No linked articles in our index yet.