WordPress Plugin Vulnerabilities

uListing < 2.0.9 - Arbitrary Blog Option Update via CSRF

Description

The plugin does not have CSRF check in the uListing_import_layout function, nor perform any validation on the option/post meta key to update to ensure it belongs to the plugin. As a result, attackers could make a logged in admin change any of the blog option (such as siteurl, blogname etc) as well as post meta to arbitrary values.

Proof of Concept

Affects Plugins

Fixed in 2.0.9

Classification

Miscellaneous

Original Researcher
WPScanTeam
Verified
Yes

Timeline

Publicly Published
2021-09-06 (about 4 years ago)
Added
2021-09-06 (about 4 years ago)
Last Updated
2021-09-06 (about 4 years ago)

Other