Directory Listings WordPress plugin – uListing, fe0fee35-4f20-4ab9-a18c-85a76a61ef09
- CVE, Research URL
- Published on
- -
- Research Description
- Directory Listings WordPress plugin – uListing [ulisting] < 2.0.9 uListing < 2.0.9 - Arbitrary Blog Option Update via CSRF The plugin does not have CSRF check in the uListing_import_layout function, nor perform any validation on the option/post meta key to update to ensure it belongs to the plugin. As a result, attackers could make a logged in admin change any of the blog option (such as siteurl, blogname etc) as well as post meta to arbitrary values.
- Affected versions
-
max 2.0.9.
- Status
-
vulnerable