CVE-2021-24725

medium

Description

The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete comments easily', which could allow attackers to make logged in admin delete arbitrary comments

References

https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=29225

https://wpscan.com/vulnerability/01483284-57f5-4ae9-b5f1-ae26b623571f

Details

Source: Mitre, NVD

Published: 2021-09-13

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00103