Far Future Expiry Header <= 1.4 - Plugin's Settings Update via Cross-Site Request Forgery

2021-10-04 00:00
apple502j

Strategic Overview

Status
Patched in 1.5
Affected Version<= 1.4
CVSS4.3Medium
CVECVE-2021-24799
View all Far Future Expiry Header vulnerabilities

Vulnerability Overview

The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

Technical Analysis

REMEDIATION: Update to version 1.5, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C