CRITICAL

CVE-2021-42359

CVSS v3

9.1

CRITICAL

EPSS Score

20.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a nonce check and was available to unauthenticated users, and did not check the post type when deleting unsubscription requests. As such, it was possible for an attacker to permanently delete an arbitrary post or page on the site by sending an AJAX request with the “action” parameter set to “admin-dismiss-unsubscribe” and the “id” parameter set to the post to be deleted. Sending such a request would move the post to the trash, and repeating the request would permanently delete the post in question.

Technical details

Published
11/5/2021

Frequently asked questions

What is CVE-2021-42359?

WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a nonce check and was available to unauthenticated users, and did not check the post type when deleting unsubscription requests. As such, it was possible for an attacker to permanently delete an arbitrary post or page on the site by sending an AJAX request with the “action” parameter set to “admin-dismiss-unsubscribe” and the “id” parameter set to the post to be deleted. Sending such a request would move the post to the trash, and repeating the request would permanently delete the post in question.

Is CVE-2021-42359 actively exploited?

Active exploitation of CVE-2021-42359 has not been confirmed. The EPSS score is 20.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-42359?

CVE-2021-42359 has a CVSS v3 base score of 9.1 (CRITICAL severity).

Is CVE-2021-42359 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.