← back
CVE-2021-24916

Qubely < 1.8.6 - Unauthenticated Arbitrary E-mail Sending

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 1.7%
exploitation probability
1.7%top 25% of all CVEs
observed exploitation
nono source reports it
The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action.
Affected products
Unknown · Qubely