First published: Mon Jan 24 2022(Updated: )
The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Etoilewebdesign Ultimate Faq | <2.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-24968.
The severity level of CVE-2021-24968 is medium.
The Ultimate FAQ WordPress plugin versions up to and exclusive of 2.1.2 are affected by CVE-2021-24968.
CVE-2021-24968 allows authenticated users with low-level roles, such as Subscriber, to create FAQ and FAQ questions.
To mitigate CVE-2021-24968, users should update to version 2.1.2 or newer of the Ultimate FAQ WordPress plugin.