Tree Sitemap (Pages, Posts & Categories list) <= 2.9 - Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation
high
The Tree Sitemap (Pages, Posts & Categories list) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthenticated attacker...
- CVSS:
- 8.8
- Affected:
- up to 2.9
- Fixed in:
- 3.1
- Disclosed:
- Apr 22, 2021
Tree Sitemap (Pages, Posts & Categories list) <= 2.9 - Missing Authorization to Arbitrary Plugin Installation/Activation
high
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugin...
- CVSS:
- 8.8
- Affected:
- up to 2.9
- Fixed in:
- 2.9
- Disclosed:
- Apr 22, 2021
CVE-2021-24192 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database