Medium severity6.5NVD Advisory· Published Feb 1, 2022· Updated Jun 17, 2026
CVE-2021-25092
CVE-2021-25092
Description
The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a CSRF attack
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:ylefebvre:link_library:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:ylefebvre:link_library:*:*:*:*:*:wordpress:*:*range: <7.2.8
- (no CPE)range: 7.2.8
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/1cd30913-67c7-46c3-a2de-dcca0c332323nvdThird Party Advisory
News mentions
0No linked articles in our index yet.