CVE-2021-20846

HIGH

Push Notifications for WordPress (Lite) <6.0.1 - CSRF

Title source: llm
STIX 2.1

Description

Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operation via a specially crafted web page.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_misc
https://delitestudio.com/en/
Product, Third Party Advisory x_refsource_misc
https://wordpress.org/plugins/push-notifications-for-wp/
Third Party Advisory x_refsource_misc
https://jvn.jp/en/jp/JVN85492429/index.html

Scores

CVSS v3 8.8
EPSS 0.0065
EPSS Percentile 46.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
delitestudio/push_notifications_for_wordpress < 6.0.1
Published Nov 24, 2021
Tracked Since Feb 18, 2026