The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1 does not check for authorisation and has a flawed CSRF logic when saving its settings, allowing any authenticated users, such as subscriber, to update them. Furthermore, due to the lack of sanitisation and escaping, it could lead to Stored Cross-Site Scripting
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-02-07T15:47:23

Updated: 2022-02-07T15:47:23

Reserved: 2021-01-14T00:00:00


Link: CVE-2021-25106

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-02-07T16:15:45.840

Modified: 2022-02-10T21:24:28.200


Link: CVE-2021-25106

JSON object: View

cve-icon Redhat Information

No data.

CWE