CVE-2021-25116
13.06.2022, 13:15
The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX action, and does not ensure that the item to be deleted is actually an asset. As a result, low privilege users such as subscriber could delete arbitrary assets, as well as put arbitrary posts in the trash.
Vendor | Product | Version |
---|---|---|
enqueue_anything_project | enqueue_anything | 𝑥 ≤ 1.0.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration