Medium severity4.3NVD Advisory· Published Jul 1, 2023· Updated Apr 8, 2026
CVE-2021-4388
CVE-2021-4388
Description
The Opal Estate plugin for WordPress is vulnerable to featured property modifications in versions up to, and including, 1.6.11. This is due to missing capability checks on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it possible for unauthenticated attackers to set and remove featured properties.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-5/nvdExploitThird Party Advisory
- www.wordfence.com/threat-intel/vulnerabilities/id/5ce729a2-a106-45ab-b96c-cfe75246def7nvdThird Party Advisory
- plugins.trac.wordpress.org/browser/opal-estate/trunk/inc/ajax-functions.phpnvdNot Applicable
News mentions
0No linked articles in our index yet.