CVE-2021-4357: uListing <= 1.6.6 - Unauthenticated Arbitrary Post/Page Deletion
The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the UlistingUserRole::saveroleapi function in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to arbitrarily delete site posts and pages.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-4357.
What is the title of the vulnerability?
The title of the vulnerability is 'The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks and a missing security nonce on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6.'
What is the severity level of CVE-2021-4357?
The severity level of CVE-2021-4357 is critical with a severity value of 5.3.
How does CVE-2021-4357 affect the uListing plugin for WordPress?
CVE-2021-4357 affects the uListing plugin for WordPress in versions up to, and including, 1.6.6.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by bypassing authorization and deleting arbitrary data.