Vulnerabilities > CVE-2021-24767 - Unspecified vulnerability in Fullworks Redirect 404 Error Page to Homepage or Custom Page With Logs

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
fullworks

Summary

The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attack

Vulnerable Configurations

Part Description Count
Application
Fullworks
31