VYPR
High severity8.8NVD Advisory· Published Nov 29, 2021· Updated Jun 17, 2026

CVE-2021-42364

CVE-2021-42364

Description

The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_page function found in the ~/stetic.php file, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 1.0.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:stetic:stetic:*:*:*:*:*:wordpress:*:*
    Range: <=1.0.6
  • WordPress/Steticllm-fuzzy
    Range: <=1.0.6
  • Stetic/Steticv5
    Range: 1.0.6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.