Vulnerabilities (CVE)

Filtered by vendor Kylephillips Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-38342 1 Kylephillips 1 Nested Pages 2023-12-18 4.3 MEDIUM 8.1 HIGH
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to trash or permanently purge arbitrary posts as well as changing their status, reassigning their ownership, and editing other metadata.