PT-2021-22062 · WordPress · Nested Pages

CVE-2021-38342

·

Published

2021-08-30

·

Updated

2023-12-18

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nested Pages WordPress plugin versions <= 3.1.15
Description The issue allows attackers to perform Cross-Site Request Forgery attacks via the npBulkAction and npBulkEdit actions, enabling them to modify posts, including trashing or purging them, changing their status, reassigning ownership, and editing metadata.
Recommendations For Nested Pages WordPress plugin versions <= 3.1.15, update to a version greater than 3.1.15 to resolve the issue. As a temporary workaround, consider restricting access to the npBulkAction and npBulkEdit admin post actions to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-38342

Affected Products

Nested Pages