The Easy Registration Forms WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the ajax_add_form function found in the ~/includes/class-form.php file which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 2.1.1.
References
Link | Resource |
---|---|
https://plugins.trac.wordpress.org/browser/easy-registration-forms/tags/2.1.1/includes/class-form.php#L256 | Third Party Advisory |
https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39353 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Wordfence
Published: 2021-11-18T00:00:00
Updated: 2021-11-19T15:34:11
Reserved: 2021-08-20T00:00:00
Link: CVE-2021-39353
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-11-19T16:15:07.847
Modified: 2021-11-24T16:23:18.757
Link: CVE-2021-39353
JSON object: View
Redhat Information
No data.
CWE