CVE-2021-4381: uListing <= 1.6.6 - Unauthenticated Options Changes via wp_route
The uListing plugin for WordPress is vulnerable to authorization bypass via wproute due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout::importnewlayout method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any WordPress option in the database.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-4381?
CVE-2021-4381 is a vulnerability in the uListing plugin for WordPress that allows for authorization bypass and potential attacks by unauthenticated users.
How severe is CVE-2021-4381?
CVE-2021-4381 is classified as critical with a severity score of 9.8.
How does CVE-2021-4381 affect the uListing plugin for WordPress?
CVE-2021-4381 affects versions up to and including 1.6.6 of the uListing plugin for WordPress.
What is the impact of CVE-2021-4381?
CVE-2021-4381 allows unauthenticated attackers to bypass authorization and potentially perform malicious actions on affected WordPress sites.
How can I mitigate the vulnerability in the uListing plugin for WordPress?
To mitigate the vulnerability in the uListing plugin for WordPress, it is recommended to update to version 1.7 or later of the plugin.