First published: Mon Feb 07 2022(Updated: )
The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call them and add arbitrary products, or change the plugin's settings for example
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Etoile Web Design Ultimate Product Catalogue | <5.0.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-24993.
The severity of CVE-2021-24993 is medium with a severity value of 6.5.
The Ultimate Product Catalog WordPress plugin version up to 5.0.26 is affected by CVE-2021-24993.
CVE-2021-24993 allows authenticated users, such as subscribers, to perform unauthorized actions like adding arbitrary products or changing the plugin's settings.
To fix CVE-2021-24993, update to version 5.0.26 or later of the Ultimate Product Catalog WordPress plugin.