← back
CVE-2021-24795CWE-352

Filter Portfolio Gallery <= 1.5 - Arbitrary Gallery Deletion via CSRF

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 0.5%
exploitation probability
0.5%top 58% of all CVEs
observed exploitation
nono source reports it
The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleting a Gallery, which could allow attackers to make a logged in admin delete arbitrary Gallery.