VulnerabilityModified
CVE-2020-13426
The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the possibility of deleting records (users) when an ID is known.
MEDIUM 6.5EPSS 1.19%
Does this matter?
Lower severity and a low EPSS score (1.19%). Track it; it rarely justifies an emergency change on its own.
Description
The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the possibility of deleting records (users) when an ID is known.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 1.19% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- bdtask/multi-scheduler
- Source
- cve@mitre.org
References
- https://0day.today/exploit/34496Broken Link
- https://cxsecurity.com/issue/WLB-2020050235Exploit, Third Party Advisory
- https://infayer.com/archivos/448Exploit, Third Party Advisory
- https://packetstormsecurity.com/files/157867/WordPress-Multi-Scheduler-1.0.0-Cross-Site-Request-Forgery.htmlExploit, Third Party Advisory, VDB Entry
- https://research-labs.net/search/exploits/wordpress-plugin-multi-scheduler-100-cross-site-request-forgery-delete-userExploit, Third Party Advisory
- https://twitter.com/UnD3sc0n0c1d0Third Party Advisory
- https://wordpress.org/plugins/multi-scheduler/#developersProduct, Third Party Advisory
- https://www.exploit-db.com/exploits/48532Exploit, Third Party Advisory, VDB Entry
- https://0day.today/exploit/34496Broken Link
- https://cxsecurity.com/issue/WLB-2020050235Exploit, Third Party Advisory
- https://infayer.com/archivos/448Exploit, Third Party Advisory
- https://packetstormsecurity.com/files/157867/WordPress-Multi-Scheduler-1.0.0-Cross-Site-Request-Forgery.htmlExploit, Third Party Advisory, VDB Entry
- https://research-labs.net/search/exploits/wordpress-plugin-multi-scheduler-100-cross-site-request-forgery-delete-userExploit, Third Party Advisory
- https://twitter.com/UnD3sc0n0c1d0Third Party Advisory
- https://wordpress.org/plugins/multi-scheduler/#developersProduct, Third Party Advisory
- https://www.exploit-db.com/exploits/48532Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.