2023-07-01 08:00:29 +00:00
{
"id" : "CVE-2021-4403" ,
"sourceIdentifier" : "security@wordfence.com" ,
"published" : "2023-07-01T06:15:10.210" ,
2023-11-07 21:03:21 +00:00
"lastModified" : "2023-11-07T03:40:52.420" ,
"vulnStatus" : "Modified" ,
2023-07-01 08:00:29 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "The Remove Schema plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the validate() function. This makes it possible for unauthenticated attackers to modify the plugins settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link."
2023-07-08 02:00:34 +00:00
} ,
{
"lang" : "es" ,
"value" : "El plugin Remove Schema para WordPress es vulnerable a ataques de tipo Cross-Site Request Forgery (CSRF) en versiones hasta la 1.5 inclusive. Esto es debido a la falta o incorrecta validaci\u00f3n nonce en la funci\u00f3n \"validate()\". Esto hace posible que atacantes no autenticados modifiquen la configuraci\u00f3n del plugin a trav\u00e9s de una solicitud manipulada concedida y puedan enga\u00f1ar a un administrador del sitio para realizar una acci\u00f3n como hacer clic en un enlace. "
2023-07-01 08:00:29 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
2023-11-07 21:03:21 +00:00
"source" : "b15e7b5b-3da4-40ae-a43c-f7aa60e62599" ,
2023-07-01 08:00:29 +00:00
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 4.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 1.4
}
]
} ,
2023-07-08 02:00:34 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:websitescanner:remove_schema:*:*:*:*:*:wordpress:*:*" ,
"versionEndIncluding" : "1.5" ,
"matchCriteriaId" : "7E90D771-1066-4961-8778-E0EBD3C5B40C"
}
]
}
]
}
] ,
2023-07-01 08:00:29 +00:00
"references" : [
{
"url" : "https://blog.nintechnet.com/25-wordpress-plugins-vulnerable-to-csrf-attacks/" ,
2023-07-08 02:00:34 +00:00
"source" : "security@wordfence.com" ,
"tags" : [
"Not Applicable"
]
2023-07-01 08:00:29 +00:00
} ,
{
"url" : "https://blog.nintechnet.com/more-wordpress-plugins-and-themes-vulnerable-to-csrf-attacks/" ,
2023-07-08 02:00:34 +00:00
"source" : "security@wordfence.com" ,
"tags" : [
"Not Applicable"
]
2023-07-01 08:00:29 +00:00
} ,
{
"url" : "https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-1/" ,
2023-07-08 02:00:34 +00:00
"source" : "security@wordfence.com" ,
"tags" : [
"Not Applicable"
]
2023-07-01 08:00:29 +00:00
} ,
{
"url" : "https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-2/" ,
2023-07-08 02:00:34 +00:00
"source" : "security@wordfence.com" ,
"tags" : [
"Not Applicable"
]
2023-07-01 08:00:29 +00:00
} ,
{
"url" : "https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-3/" ,
2023-07-08 02:00:34 +00:00
"source" : "security@wordfence.com" ,
"tags" : [
"Third Party Advisory"
]
2023-07-01 08:00:29 +00:00
} ,
{
"url" : "https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-4/" ,
2023-07-08 02:00:34 +00:00
"source" : "security@wordfence.com" ,
"tags" : [
"Not Applicable"
]
2023-07-01 08:00:29 +00:00
} ,
{
"url" : "https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-5/" ,
2023-07-08 02:00:34 +00:00
"source" : "security@wordfence.com" ,
"tags" : [
"Not Applicable"
]
2023-07-01 08:00:29 +00:00
} ,
{
"url" : "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2548575%40remove-schema&new=2548575%40remove-schema&sfp_email=&sfph_mail=" ,
2023-07-08 02:00:34 +00:00
"source" : "security@wordfence.com" ,
"tags" : [
"Patch"
]
2023-07-01 08:00:29 +00:00
} ,
{
"url" : "https://www.wordfence.com/threat-intel/vulnerabilities/id/89635463-966d-4f7d-995d-ad83a502d95b?source=cve" ,
2023-07-08 02:00:34 +00:00
"source" : "security@wordfence.com" ,
"tags" : [
"Third Party Advisory"
]
2023-07-01 08:00:29 +00:00
}
]
}