CVE-2021-4339
Last modified
CVE-2021-4339 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file on the /1/api/ulisting-user/search REST-API route in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to retrieve the list of all users and their email address in the database.. EPSS estimates a 0.95% chance of exploitation in the next 30 days.
Description
The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file on the /1/api/ulisting-user/search REST-API route in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to retrieve the list of all users and their email address in the database.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Stylemixthemes | Ulisting | <= 1.6.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-4339?
How severe is CVE-2021-4339?
How do I fix CVE-2021-4339?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-43361Improper Neutralization of Special Elements used in an SQL C…9.8
- CVE-2021-43362Improper Neutralization of Special Elements used in an SQL C…9.8
- CVE-2021-4337Sixteen XforWooCommerce Add-On Plugins for WordPress are vul…8.8
- CVE-2021-4338The 404 to 301 plugin for WordPress is vulnerable to authori…5.4
- CVE-2021-43388Unisys Cargo Mobile Application before 1.2.29 uses cleartext…7.5
- CVE-2021-43389An issue was discovered in the Linux kernel before 5.14.15. …5.5
- CVE-2021-43390An Out-of-Bounds Write vulnerability exists when reading a D…7.8
- CVE-2021-43391An Out-of-Bounds Read vulnerability exists when reading a DX…7.8
- CVE-2021-43392STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN…6.2
- CVE-2021-43393STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN…6.2
- CVE-2021-43394Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC…9.8
- CVE-2021-43395An issue was discovered in illumos before f859e7171bb5db3432…5.5
Are you affected by CVE-2021-4339?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
