Description
The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-11661 | The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack. |
References
History
Fri, 30 Jan 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kaizencoders
Kaizencoders url Shortify |
|
| CPEs | cpe:2.3:a:kaizencoders:url_shortify:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Kazencoders
Kazencoders url Shortify |
Kaizencoders
Kaizencoders url Shortify |
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T19:42:16.664Z
Reserved: 2021-01-14T00:00:00.000Z
Link: CVE-2021-24749
No data.
Status : Analyzed
Published: 2021-11-29T09:15:07.257
Modified: 2026-01-30T16:52:02.850
Link: CVE-2021-24749
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD