CVE-2021-24916
Qubely < 1.8.6 - Unauthenticated Arbitrary E-mail Sending
Record summary
CVE-2021-24916 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 15, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
QubelyDefault status: unaffected | CVE List | Before 1.8.6 | affected |
Nuclei templates
1ProjectDiscoveryHIGHWordPress Qubely < 1.8.6 - Unauthenticated Email SendingCVSS 5.3
Qubely WordPress plugin < 1.8.6 contains an insecure deserialization caused by unauthenticated users being able to send arbitrary emails via the qubely_send_form_data AJAX action, letting attackers send spam or malicious emails, exploit requires no authentication.
Impact
Attackers can send spam or malicious emails from the server, potentially leading to spam blacklisting or abuse.
Remediation
Update to version 1.8.6 or later
Source: ProjectDiscovery