Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-4370

Опубликовано: 07 июн. 2023
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack security nonces, and data is seldom validated. This issue exists in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to conduct numerous administrative actions, including those less critical than the explicitly outlined ones in our detection.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:stylemixthemes:ulisting:*:*:*:*:*:wordpress:*:*
Версия до 1.6.6 (включая)

EPSS

Процентиль: 55%
0.00323
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 9.8
github
больше 2 лет назад

The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack security nonces, and data is seldom validated. This issue exists in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to conduct numerous administrative actions, including those less critical than the explicitly outlined ones in our detection.

EPSS

Процентиль: 55%
0.00323
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-862