First published: Wed Jun 07 2023(Updated: )
The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to arbitrarily delete site posts and pages.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Stylemixthemes Ulisting | <=1.6.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-4357.
The title of the vulnerability is 'The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks and a missing security nonce on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6.'
The severity level of CVE-2021-4357 is critical with a severity value of 5.3.
CVE-2021-4357 affects the uListing plugin for WordPress in versions up to, and including, 1.6.6.
An attacker can exploit this vulnerability by bypassing authorization and deleting arbitrary data.