First published: Wed Jun 07 2023(Updated: )
The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. This is due to the stm_listing_register AJAX action function being accessible and taking roles unprotected. This makes it possible for unauthenticated attackers to create accounts, even those with administrator privileges.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
StylemixThemes uListing | <=1.6.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-4343 refers to a vulnerability in the Unauthenticated Account Creation plugin for WordPress, allowing unauthenticated users to create accounts.
CVE-2021-4343 has a severity rating of 9.8, which is classified as critical.
CVE-2021-4343 affects versions up to and including 1.6.6 of the Unauthenticated Account Creation plugin for WordPress.
To fix CVE-2021-4343, update the Unauthenticated Account Creation plugin to a version beyond 1.6.6.
You can find more information about CVE-2021-4343 at the following references: [Blog post](https://blog.nintechnet.com/wordpress-ulisting-plugin-fixed-multiple-critical-vulnerabilities/), [Plugin changeset](https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2456786%40ulisting&new=2456786%40ulisting&sfp_email=&sfph_mail=), [Wordfence threat intel](https://www.wordfence.com/threat-intel/vulnerabilities/id/1c6bf45b-b02d-43bb-b682-7f1ae994e1d3?source=cve).