Логотип exploitDog
bind:CVE-2021-4346
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-4346

Количество 2

Количество 2

nvd логотип

CVE-2021-4346

больше 2 лет назад

The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible for unauthenticated attackers to edit any account on the blog, such as changing the admin account's email address.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-f7xc-mx7q-rc22

больше 2 лет назад

The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible for unauthenticated attackers to edit any account on the blog, such as changing the admin account's email address.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-4346

The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible for unauthenticated attackers to edit any account on the blog, such as changing the admin account's email address.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-f7xc-mx7q-rc22

The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible for unauthenticated attackers to edit any account on the blog, such as changing the admin account's email address.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу