CVE Database /
CVE-2021-24749
CVE · Medium
CVE-2021-24749 — URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.5.11
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24749
|
URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.5.11 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 1.5.11
|
1.5.11 |
2021-10-28 |
—
|
CVE-2021-24749
The URL Shortify plugin prior to version 1.5.11 lacks proper cross-site request forgery protection on its bulk deletion functionality for both links and groups. An attacker could exploit this vulnerability to trick an authenticated administrator into inadvertently removing arbitrary links and groups through a malicious request. The absence of CSRF tokens or verification allows unauthorized deletion operations to be performed without the admin's knowledge or consent.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings