First published: Mon Aug 07 2023(Updated: )
The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Themeum Qubely | <1.8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24916 is a vulnerability in the Qubely WordPress plugin before version 1.8.6 that allows an unauthenticated user to send arbitrary emails to arbitrary addresses via the qubely_send_form_data AJAX action.
The severity of CVE-2021-24916 is high, with a severity score of 7.5.
The Qubely WordPress plugin before version 1.8.6 is affected by CVE-2021-24916.
To fix CVE-2021-24916, you should update the Qubely WordPress plugin to version 1.8.6 or later.
You can find more information about CVE-2021-24916 at the following reference: [link](https://wpscan.com/vulnerability/93b893be-59ad-4500-8edb-9fa7a45304d5).