First published: Tue Jul 27 2021(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Stylemixthemes Ulisting | <=2.0.5 |
Update to 2.0.6 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36878 is a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress uListing plugin, specifically versions <= 2.0.5.
The CVE-2021-36878 vulnerability in WordPress uListing allows attackers to update settings using Cross-Site Request Forgery (CSRF) attacks.
CVE-2021-36878 has a severity keyword of 'medium' and a severity value of 4.3.
To fix the CVE-2021-36878 vulnerability, update your WordPress uListing plugin to a version higher than 2.0.5.
You can find more information about the CVE-2021-36878 vulnerability and its patch in the references provided: [link 1](https://patchstack.com/database/vulnerability/ulisting/wordpress-ulisting-plugin-2-0-5-settings-update-via-cross-site-request-forgery-csrf-vulnerability), [link 2](https://wordpress.org/plugins/ulisting/#developers).