The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings, Denial-of-Service, as well as arbitrary image conversion
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/972f8c5d-22b7-42de-a981-2e5acb72297b | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-11-23 12:15
Updated : 2021-11-24 07:25
NVD link : CVE-2021-24641
Mitre link : CVE-2021-24641
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
imagestowebp_project
- images_to_webp