CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. It affects WordPress.
CVE
CVE-2021-24133
Severity
MEDIUM
CVSS
4.3
EPSS
0.47%
WordPress
Original NVD Description
Lack of CSRF checks in the ActiveCampaign WordPress plugin, versions before 8.0.2, on its Settings form, which could allow attacker to make a logged-in administrator change API Credentials to attacker's account.
Related CVEs
Other vulnerabilities affecting the same vendor(s)