CVE-2021-4345: uListing <= 1.6.6 - Unauthenticated Arbitrary Roles and Capabilities Creation/Deletion
Published Jun 7, 2023
·Updated
The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on the UlistingUserRole::saveroleapi method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to remove or add roles, and add capabilities.
Affected Software
1 affected component
StylemixThemes Ulisting Wordpress<=1.6.6
Remediation
Event History
Jun 7, 2023
CVE Published
via MITRE·01:51 AM
Data Sourced
via MITRE·01:51 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this uListing plugin for WordPress vulnerability?
The vulnerability ID is CVE-2021-4345.
2
What is the severity of CVE-2021-4345?
The severity of CVE-2021-4345 is medium with a severity value of 5.3.
3
What is the affected software for CVE-2021-4345?
The affected software for CVE-2021-4345 is the uListing plugin for WordPress, versions up to and including 1.6.6.
4
What is the impact of CVE-2021-4345?
CVE-2021-4345 allows unauthenticated attackers to remove or add roles, and add capabilities.
5
How can I fix CVE-2021-4345?
To fix CVE-2021-4345, update the uListing plugin for WordPress to version 1.6.7 or newer.