cve/2021/CVE-2021-24766.md
2024-06-18 02:51:15 +02:00

859 B
Raw Blame History

CVE-2021-24766

Description

The 404 to 301 Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place when cleaning the logs, which could allow attacker to make a logged in admin delete all of them via a CSRF attack

POC

Reference

Github

No PoCs found on GitHub currently.