The Edwiser Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,2.0.6. This is due to missing or incorrect nonce validation on the user_data_synchronization_initiater(), course_synchronization_initiater(), users_link_to_moodle_synchronization(), connection_test_initiater(), admin_menus(), and subscribe_handler() function. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
We have discovered 98 live websites that are affected by CVE-2021-4399.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 98 live websites (100% of Edwiser Bridge install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
| 30 websites | |
| 9 websites | |
| 8 websites | |
| 8 websites | |
| 5 websites | |
| 5 websites | |
| 4 websites | |
| 3 websites | |
| 3 websites | |
| 2 websites |
| .com | 37 websites |
| .org | 12 websites |
| .co.uk | 5 websites |
| .es | 5 websites |
| .com.br | 4 websites |
| .eu | 4 websites |
| .net | 4 websites |
| .com.au | 3 websites |
| .pl | 2 websites |
| .de | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.pl | ***,*** | ||
| ***************.org | ***,*** | ||
| ******.net | *,***,*** | ||
| ******.es | *,***,*** | ||
| *************.org | *,***,*** | ||
| ***********************.com | *,***,*** | ||
| ************.**.uk | *,***,*** | ||
| **********.pl | *,***,*** | ||
| **********.***.au | *,***,*** | ||
| *******************.com | *,***,*** |
FAQ