The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authenticated users, such as subscriber to delete arbitrary publication
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2022-02-01T00:00:00

Updated: 2024-08-03T19:56:11.072Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-25097

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-02-01T13:15:09.557

Modified: 2022-12-09T18:08:26.397

Link: CVE-2021-25097

cve-icon Redhat

No data.