Vulnerability Description
The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any authenticated users to delete arbitrary page/post and booking via an IDOR vector.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Purethemes | Listeo | < 1.6.11 |
Related Weaknesses (CWE)
References
- https://m0ze.ru/vulnerability/%5B2021-02-10%5D-%5BWordPress%5D-%5BCWE-639%5D-LisExploitThird Party Advisory
- https://wpscan.com/vulnerability/9afa7e11-68b3-4196-975e-8b3f8e68ce56ExploitThird Party Advisory
- https://m0ze.ru/vulnerability/%5B2021-02-10%5D-%5BWordPress%5D-%5BCWE-639%5D-LisExploitThird Party Advisory
- https://wpscan.com/vulnerability/9afa7e11-68b3-4196-975e-8b3f8e68ce56ExploitThird Party Advisory
FAQ
What is CVE-2021-24318?
CVE-2021-24318 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any authenticated users to delete arbitrary page/post a...
How severe is CVE-2021-24318?
CVE-2021-24318 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24318?
Check the references section above for vendor advisories and patch information. Affected products include: Purethemes Listeo.