Vulnerability Details CVE-2021-24795
The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleting a Gallery, which could allow attackers to make a logged in admin delete arbitrary Gallery.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.1%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.3
Products affected by CVE-2021-24795
-
cpe:2.3:a:phoeniixx:filter_portfolio_gallery:-
-
cpe:2.3:a:phoeniixx:filter_portfolio_gallery:1.5