Record summary

CVE-2021-24916 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 15, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Qubely

Default status: unaffected

CVE ListBefore 1.8.6affected

Nuclei templates

1
ProjectDiscoveryHIGHWordPress Qubely < 1.8.6 - Unauthenticated Email SendingCVSS 5.3

Qubely WordPress plugin < 1.8.6 contains an insecure deserialization caused by unauthenticated users being able to send arbitrary emails via the qubely_send_form_data AJAX action, letting attackers send spam or malicious emails, exploit requires no authentication.

Impact

Attackers can send spam or malicious emails from the server, potentially leading to spam blacklisting or abuse.

Remediation

Update to version 1.8.6 or later

WeaknessesCWE-284
Authorsroberto
Template tagscvecve2021wordpresswp-pluginqubelywpemailunauth
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
FOFA: body="qubely_urls"

Source: ProjectDiscovery

References

2