AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-38342

HIGH · CVSS 8.1 EPSS 0.49%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-08-30 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-38342
Severity
HIGH
CVSS
8.1
EPSS
0.49%
WordPress

Original NVD Description

The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to trash or permanently purge arbitrary posts as well as changing their status, reassigning their ownership, and editing other metadata.

Related CVEs

Other vulnerabilities affecting the same vendor(s)