CVE-2021-25013: Qubely < 1.7.8 - Subscriber+ Arbitrary Post Deletion
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubelydeletesavedblock AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary posts
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25013?
CVE-2021-25013 is a vulnerability in the Qubely WordPress plugin before version 1.7.8 that allows authenticated users to delete arbitrary posts.
How severe is CVE-2021-25013?
CVE-2021-25013 has a severity level of medium with a CVSS score of 6.5.
How does CVE-2021-25013 affect the Qubely WordPress plugin?
CVE-2021-25013 affects the Qubely WordPress plugin before version 1.7.8 by not having authorization and CSRF checks on a specific AJAX action, allowing authenticated users to delete arbitrary posts.
Which version of the Qubely WordPress plugin is affected by CVE-2021-25013?
CVE-2021-25013 affects the Qubely WordPress plugin up to version 1.7.8.
How can I fix CVE-2021-25013?
To fix CVE-2021-25013, update the Qubely WordPress plugin to version 1.7.8 or newer.