CVE-2021-4399

The Edwiser Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,2.0.6. This is due to missing or incorrect nonce validation on the user_data_synchronization_initiater(), course_synchronization_initiater(), users_link_to_moodle_synchronization(), connection_test_initiater(), admin_menus(), and subscribe_handler() function. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.


We have discovered 98 live websites that are affected by CVE-2021-4399.

Run a Free Instant Scan




Affected Software

Product  Edwiser Bridge
Category Wordpress Plugins
Vulnerable Domains98 live websites (100% of Edwiser Bridge install base)
Vulnerable Versions
  • from 0 through 2.0.6
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)



Details

  • Published - Jul 1, 2023
  • Updated - Oct 28, 2024

Credits

  • Jerome Bruandet (finder)

Website Distribution by Country

Number of websites using CVE-2021-4399
United States30 websites



Spain9 websites
Germany8 websites
GB8 websites
Australia5 websites
France5 websites
Brazil4 websites
Ireland3 websites
Poland3 websites
Cyprus2 websites

Website Distribution by TLD

Number of websites using CVE-2021-4399
.com37 websites
.org12 websites
.co.uk5 websites
.es5 websites
.com.br4 websites
.eu4 websites
.net4 websites
.com.au3 websites
.pl2 websites
.de1 websites

Websites affected by CVE-2021-4399

Top websites that are affected by CVE-2021-4399. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.pl Poland***,***
***************.org United States***,***
******.net Germany*,***,***
******.es Spain*,***,***
*************.org United States*,***,***
***********************.com GB*,***,***
************.**.uk GB*,***,***
**********.pl Poland*,***,***
**********.***.au Australia*,***,***
*******************.com United States*,***,***
See full domain list

FAQ

A total of 98 websites have been identified as vulnerable to CVE-2021-4399, based on global website indexing conducted by WebTechSurvey.
The Edwiser Bridge is affected by the CVE-2021-4399 vulnerability.
Edwiser Bridge versions up to and including 2.0.6 are vulnerable to CVE-2021-4399.

References