Better Search <= 2.5.2 - Cross-Site Request Forgery to Settings Import
2021-03-01 00:00
Jerome BruandetStrategic Overview
StatusPatched in 2.5.3
Affected PluginBetter Search – Relevant search results for WordPress
Affected Version
< 2.5.3CVSS8.8High
CVE
CVE-2021-4373Vulnerability Overview
The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to import settings via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Technical Analysis
REMEDIATION: Update to version 2.5.3, or a newer patched version --- IDENTIFIER: CWE-288 (Authentication Bypass Using an Alternate Path or Channel) The product requires authentication, but the product has an alternate path or channel that does not require authentication.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C