Directory Listings WordPress plugin – uListing, 8a11b9d58c9b10f71357009e0e9eb49124c78ba9
- CVE, Research URL
- Published on
- Jan 28, 2021
- Research Description
- Directory Listings WordPress plugin – uListing [ulisting] < 1.7 uListing <= 1.6.6 - Unauthenticated Arbitrary Account Creation The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. This is due to the stm_listing_register AJAX action function being accessible and taking roles unprotected. This makes it possible for unauthenticated attackers to create accounts, even those with administrator privileges.
- Affected versions
-
max 1.7.
- Status
-
vulnerable