CVE · Medium

CVE-2021-24446 — Remove Footer Credit [remove-footer-credit] < 1.0.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24446 Remove Footer Credit [remove-footer-credit] < 1.0.11 Cross-Site Request Forgery (CSRF) Medium 5.4 < 1.0.11 1.0.11 2021-07-12

CVE-2021-24446

The Remove Footer Credit plugin before version 1.0.11 contained a cross-site request forgery vulnerability in its settings save functionality that could be exploited to modify plugin configuration without proper verification. Additionally, the plugin failed to properly sanitize user input when storing settings, creating an authenticated stored cross-site scripting vulnerability that allowed attackers with admin access to inject malicious code.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.