First published: Wed Jun 07 2023(Updated: )
The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on the UlistingUserRole::save_role_api method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to remove or add roles, and add capabilities.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Stylemixthemes Ulisting | <=1.6.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-4345.
The severity of CVE-2021-4345 is medium with a severity value of 5.3.
The affected software for CVE-2021-4345 is the uListing plugin for WordPress, versions up to and including 1.6.6.
CVE-2021-4345 allows unauthenticated attackers to remove or add roles, and add capabilities.
To fix CVE-2021-4345, update the uListing plugin for WordPress to version 1.6.7 or newer.