CVE-2021-42364
The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_page function found in the ~/stetic.php file, which made it possible for attackers to inject arbitrary web scripts in versions up to,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_page function found in the ~/stetic.php file, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 1.0.6.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- stetic/stetic
- Source
- security@wordfence.com
References
- https://plugins.trac.wordpress.org/browser/stetic/trunk/stetic.php#L129Third Party Advisory
- https://wordfence.com/vulnerability-advisories/#CVE-2021-42364Third Party Advisory
- https://plugins.trac.wordpress.org/browser/stetic/trunk/stetic.php#L129Third Party Advisory
- https://wordfence.com/vulnerability-advisories/#CVE-2021-42364Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.