CVE-2021-36877: WordPress uListing plugin <= 2.0.5 - Modify User Roles via Cross-Site Request Forgery (CSRF) vulnerability
Published Sep 27, 2021
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles.
Affected Software
1 affected component
StylemixThemes Ulisting Wordpress<=2.0.5
Remediation
Information
Update to 2.0.6 or higher version.
Event History
Sep 27, 2021
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-36877?
The severity of CVE-2021-36877 is medium, with a severity value of 6.5.
2
What is the vulnerability in WordPress uListing plugin?
The vulnerability in WordPress uListing plugin is a Cross-Site Request Forgery (CSRF) vulnerability.
3
What version of the uListing plugin is affected by CVE-2021-36877?
The uListing plugin version 2.0.5 and below are affected by CVE-2021-36877.
4
How can attackers exploit CVE-2021-36877?
Attackers can exploit CVE-2021-36877 to modify user roles through Cross-Site Request Forgery (CSRF) attacks.
5
How can I fix CVE-2021-36877 in uListing plugin?
To fix CVE-2021-36877 in uListing plugin, update to a version higher than 2.0.5.