CVE Published: 01/11/2021 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: WPScan |
Vendor: Unknown |
Product: Delete All Comments Easily Status : PUBLISHED
CVE-2020-36505 Description
The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blog.