CVE-2021-4374: WordPress Automatic Plugin <= 3.53.2 - Unauthenticated Arbitrary Options Update
The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option validation in the processform.php file. This makes it possible for unauthenticated attackers to arbitrarily update the settings of a vulnerable site and ultimately compromise the entire site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-4374?
The severity of CVE-2021-4374 is considered high due to its potential for arbitrary options updates by unauthenticated attackers.
How do I fix CVE-2021-4374?
To fix CVE-2021-4374, update the WordPress Automatic Plugin to version 3.54 or later.
Who is affected by CVE-2021-4374?
CVE-2021-4374 affects all versions of the WordPress Automatic Plugin up to and including 3.53.2.
What type of vulnerability is CVE-2021-4374?
CVE-2021-4374 is classified as an authorization and option validation vulnerability.
Can CVE-2021-4374 be exploited remotely?
Yes, CVE-2021-4374 can be exploited remotely by unauthenticated attackers.