First published: Mon Sep 27 2021(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Stylemixthemes Ulisting | <=2.0.5 |
Update to 2.0.6 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-36877 is medium, with a severity value of 6.5.
The vulnerability in WordPress uListing plugin is a Cross-Site Request Forgery (CSRF) vulnerability.
The uListing plugin version 2.0.5 and below are affected by CVE-2021-36877.
Attackers can exploit CVE-2021-36877 to modify user roles through Cross-Site Request Forgery (CSRF) attacks.
To fix CVE-2021-36877 in uListing plugin, update to a version higher than 2.0.5.