Vulnerabilities > CVE-2020-36505 - Unspecified vulnerability in Delete ALL Comments Easily Project Delete ALL Comments Easily 1.3
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blog.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
References
- https://medium.com/%40hoanhp/0-day-story-2-delete-all-comments-easily-a854e52a7d50
- https://medium.com/%40hoanhp/0-day-story-2-delete-all-comments-easily-a854e52a7d50
- https://wpscan.com/vulnerability/239f8efa-8fa4-4274-904f-708e65083821
- https://wpscan.com/vulnerability/239f8efa-8fa4-4274-904f-708e65083821