Directory Listings WordPress plugin – uListing, eb9fdc26-e382-46cc-966e-407ad93dc360
- CVE, Research URL
- Published on
- -
- Research Description
- Directory Listings WordPress plugin – uListing [ulisting] < 1.7 uListing < 1.7 - Unauthenticated Arbitrary Account Change The AJAX action stm_listing_profile_edit() accessible to both authenticated and unauthenticated users did not perform capability and CSRF checks, and did not ensure that the edited account belonged to the user making the request. This allows unauthenticated users to update arbitrary accounts, such as changing their email addresses or profile picture
- Affected versions
-
max 1.7.
- Status
-
vulnerable