The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to trash or permanently purge arbitrary posts as well as changing their status, reassigning their ownership, and editing other metadata.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-24795 | The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to trash or permanently purge arbitrary posts as well as changing their status, reassigning their ownership, and editing other metadata. |
Fixes
Solution
Update to Version 3.1.16
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-09-17T00:56:54.133Z
Reserved: 2021-08-09T00:00:00.000Z
Link: CVE-2021-38342
No data.
Status : Modified
Published: 2021-08-30T19:15:09.263
Modified: 2024-11-21T06:16:51.260
Link: CVE-2021-38342
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD