CVE · Medium

CVE-2021-24749 — URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.5.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24749 URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.5.11 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.5.11 1.5.11 2021-10-28

CVE-2021-24749

The URL Shortify plugin prior to version 1.5.11 lacks proper cross-site request forgery protection on its bulk deletion functionality for both links and groups. An attacker could exploit this vulnerability to trick an authenticated administrator into inadvertently removing arbitrary links and groups through a malicious request. The absence of CSRF tokens or verification allows unauthorized deletion operations to be performed without the admin's knowledge or consent.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.