CVE-2021-4346: uListing <= 1.6.6 - Unauthenticated Arbitrary Account Changes
The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stmlistingprofileedit AJAX action. This makes it possible for unauthenticated attackers to edit any account on the blog, such as changing the admin account's email address.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-4346.
What is the severity of CVE-2021-4346?
The severity of CVE-2021-4346 is critical with a CVSS score of 7.5.
What is affected by CVE-2021-4346?
The uListing plugin for WordPress versions up to and including 1.6.6 is affected by CVE-2021-4346.
How can an attacker exploit CVE-2021-4346?
Unauthenticated attackers can exploit CVE-2021-4346 by editing any account on the affected blog.
Are there any fixes or patches available for CVE-2021-4346?
Yes, a fix is available for CVE-2021-4346. It is recommended to update the uListing plugin for WordPress to the latest version.