First published: Wed Jun 07 2023(Updated: )
The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option validation in the process_form.php file. This makes it possible for unauthenticated attackers to arbitrarily update the settings of a vulnerable site and ultimately compromise the entire site.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Valvepress Wordpress Automatic Plugin | <=3.53.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-4374 is considered high due to its potential for arbitrary options updates by unauthenticated attackers.
To fix CVE-2021-4374, update the WordPress Automatic Plugin to version 3.54 or later.
CVE-2021-4374 affects all versions of the WordPress Automatic Plugin up to and including 3.53.2.
CVE-2021-4374 is classified as an authorization and option validation vulnerability.
Yes, CVE-2021-4374 can be exploited remotely by unauthenticated attackers.