Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Enqueue Anything Project Subscribe
Filtered by product Enqueue Anything
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-25116 1 Enqueue Anything Project 1 Enqueue Anything 2022-06-17 4.0 MEDIUM 6.5 MEDIUM
The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX action, and does not ensure that the item to be deleted is actually an asset. As a result, low privilege users such as subscriber could delete arbitrary assets, as well as put arbitrary posts in the trash.