Fiche vulnérabilité
CVE-2021-25093 : faille élevée ylefebvre link library (CVSS 7.5)
Description
The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 1 févr. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- ylefebvre link library