plugin

Ulisting Vulnerabilities

76 known security issues reported for the Ulisting WordPress plugin. Most recent disclosed Jul 22, 2026.

9 critical 7 high 13 medium

Running Ulisting on your site? Check whether your installed version is affected.

Scan your site free

Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization

medium

The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized act...

CVSS:
4.3
Affected:
up to 2.2.0
Fix:
No patched version reported
Disclosed:
Jul 22, 2026

CVE-2026-27391 on NVD →

Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization

medium

The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized ac...

CVSS:
4.3
Affected:
up to 2.2.0
Fix:
No patched version reported
Disclosed:
Jul 22, 2026

CVE-2026-27392 on NVD →

uListing - Arbitrary File Download vulnerability

medium

Arbitrary File Download vulnerability

CVSS:
4.9
Affected:
up to 2.2.0
Fix:
No patched version reported
Disclosed:
Feb 26, 2026

Directory Listings WordPress plugin – uListing <= 2.2.0 - Authenticated (Editor+) Arbitrary File Download

medium

The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with Editor-level access and above, to read the contents of arbitrary files on the server, which can contain sensi...

CVSS:
4.9
Affected:
up to 2.2.0
Fix:
No patched version reported
Disclosed:
Feb 26, 2026

CVE-2026-28078 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] <= 2.2.0 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects uListing: from n/a through <= 2.2.0.

Affected:
up to 2.2.0
Fix:
No patched version reported
Disclosed:
Feb 26, 2026

CVE-2026-28138 on NVD →

uListing <= 2.2.0 - Authenticated (Administrator+) PHP Object Injection

medium

The uListing plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable s...

CVSS:
6.6
Affected:
up to 2.2.0
Fix:
No patched version reported
Disclosed:
Apr 22, 2025

CVE-2026-28138 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] <= 2.2.0 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in Stylemix uListing allows Object Injection. This issue affects uListing: from n/a through 2.2.0.

Affected:
up to 2.2.0
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2025-32662 on NVD →

uListing <= 2.2.0 - Authenticated (Subscriber+) PHP Object Injection

high

The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known P...

CVSS:
8.8
Affected:
up to 2.2.0
Fix:
No patched version reported
Disclosed:
Apr 15, 2025

CVE-2025-32662 on NVD →

uListing <= 2.1.9 - Authenticated (Administrator+) SQL Injection

medium

The uListing plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and abov...

CVSS:
4.9
Affected:
up to 2.1.9
Fix:
No patched version reported
Disclosed:
Apr 4, 2025

CVE-2025-32122 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] <= 2.2.0 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing allows Blind SQL Injection. This issue affects uListing: from n/a through 2.1.9.

Affected:
up to 2.2.0
Fix:
No patched version reported
Disclosed:
Apr 4, 2025

CVE-2025-32122 on NVD →

Directory Listings WordPress plugin – uListing <= 2.2.0 - Authenticated (Subscriber+) Privilege Escalation

high

The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.0. This is due to the stm_listing_profile_edit AJAX action not having enough restriction on the user meta that can be updated. This makes it possible for authenticated...

CVSS:
8.8
Affected:
up to 2.2.0
Fix:
No patched version reported
Disclosed:
Mar 14, 2025

CVE-2025-1653 on NVD →

Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Update and PHP Object Injection

high

The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized modification of data and PHP Object Injection due to a missing capability check on the stm_listing_ajax AJAX action in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with...

CVSS:
8.8
Affected:
up to 2.2.0
Fix:
No patched version reported
Disclosed:
Mar 14, 2025

CVE-2025-1657 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 2.1.7

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing allows Blind SQL Injection. This issue affects uListing: from n/a through 2.1.6.

Affected:
up to 2.1.7
Fixed in:
2.1.7
Disclosed:
Mar 3, 2025

CVE-2025-25150 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 2.1.7

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes uListing allows SQL Injection. This issue affects uListing: from n/a through 2.1.6.

Affected:
up to 2.1.7
Fixed in:
2.1.7
Disclosed:
Feb 7, 2025

CVE-2025-25151 on NVD →

uListing <= 2.1.6 - Unauthenticated SQL Injection

high

The uListing plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into a...

CVSS:
7.5
Affected:
up to 2.1.6
Fixed in:
2.1.7
Disclosed:
Feb 3, 2025

CVE-2025-25150 on NVD →

uListing <= 2.1.6 - Authenticated (Contributor+) SQL Injection

medium

The uListing plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above,...

CVSS:
6.5
Affected:
up to 2.1.6
Fixed in:
2.1.7
Disclosed:
Feb 3, 2025

CVE-2025-25151 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 2.1.6

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StylemixThemes uListing.This issue affects uListing: from n/a through 2.1.5.

Affected:
up to 2.1.6
Fixed in:
2.1.6
Disclosed:
Oct 7, 2024

CVE-2024-47344 on NVD →

uListing <= 2.1.5 - Unauthenticated Information Exposure

medium

The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.5 via the /pricing-plan/payment endpoint. This makes it possible for unauthenticated attackers to render the pricing plan payment page.

CVSS:
5.3
Affected:
up to 2.1.5
Fixed in:
2.1.6
Disclosed:
Sep 27, 2024

CVE-2024-47344 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

[en] The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible for unauthenticated attackers to edit any account on the blog, such as changi...

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jun 7, 2023

CVE-2021-4346 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

[en] The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout::import_new_layout method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any Wo...

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jun 7, 2023

CVE-2021-4381 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

[en] The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack security nonces, and data is seldom validated. This issue exists in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to condu...

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jun 7, 2023

CVE-2021-4370 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

[en] The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac...

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jun 7, 2023

CVE-2021-4340 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

[en] The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. This is due to the stm_listing_register AJAX action function being accessible and taking roles unprotected. This makes it possible for unauthenticated attackers to cr...

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jun 7, 2023

CVE-2021-4343 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

[en] The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on the UlistingUserRole::save_role_api method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to remove or add roles, and add capabilities.

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jun 7, 2023

CVE-2021-4345 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

[en] The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to arbitrarily delete site posts and...

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jun 7, 2023

CVE-2021-4357 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

[en] The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm_update_email_data AJAX action in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change...

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jun 7, 2023

CVE-2021-4341 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

[en] The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file on the /1/api/ulisting-user/search REST-API route in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to retrieve the list of...

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jun 7, 2023

CVE-2021-4339 on NVD →

uListing <= 1.6.6 - Unauthenticated SQL Injection

critical

The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers...

CVSS:
9.8
Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Oct 28, 2021

CVE-2021-4340 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers...

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Oct 28, 2021

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 2.0.4

unknown

[en] Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom.

Affected:
up to 2.0.4
Fixed in:
2.0.4
Disclosed:
Sep 27, 2021

CVE-2021-36880 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 2.0.6

unknown

[en] Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration.

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Sep 27, 2021

CVE-2021-36879 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 2.0.6

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles.

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Sep 27, 2021

CVE-2021-36877 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 2.0.6

unknown

[en] Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks CSRF checks on plugin administration pages.

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Sep 27, 2021

CVE-2021-36876 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 2.0.6

unknown

[en] Cross-site Scripting (XSS) vulnerability in Stylemix Directory Listings WordPress plugin – uListing allows Reflected XSS.This issue affects Directory Listings WordPress plugin – uListing: from n/a through 2.0.5.

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Sep 27, 2021

CVE-2021-36875 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 2.0.6

unknown

[en] Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5).

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Sep 27, 2021

CVE-2021-36874 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 2.0.6

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings.

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Sep 27, 2021

CVE-2021-36878 on NVD →

Listing, Classified Ads & Business Directory – uListing <= 2.0.8 - Cross-Site Request Forgery

high

The Listing, Classified Ads & Business Directory – uListing plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.8. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to edit blog settings and...

CVSS:
8.8
Affected:
up to 2.0.8
Fixed in:
2.0.9
Disclosed:
Sep 6, 2021

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 2.0.9

unknown

The Listing, Classified Ads & Business Directory – uListing plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.8. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to edit blog settings and...

Affected:
up to 2.0.9
Fixed in:
2.0.9
Disclosed:
Sep 6, 2021

Listing, Classified Ads & Business Directory – uListing <= 2.0.5 - Privilege Escalation

critical

Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration.

CVSS:
9.8
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Jul 27, 2021

CVE-2021-36879 on NVD →

uListing <= 2.0.5 - Cross-Site Request Forgery leading to Settings Change

medium

The Cross-Site Request Forgery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to make changes to the plugin's settings via forged request granted they can trick a site administrator into performing an action...

CVSS:
4.3
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Jul 27, 2021

CVE-2021-36878 on NVD →

Listing, Classified Ads & Business Directory – uListing <= 2.0.5 - Cross-Site Request Forgery

medium

Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles.

CVSS:
6.5
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Jul 27, 2021

CVE-2021-36877 on NVD →

Listing, Classified Ads & Business Directory – uListing <= 2.0.5 - Cross-Site Request Forgery

medium

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks CSRF checks on plugin administration pages.

CVSS:
5.4
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Jul 27, 2021

CVE-2021-36876 on NVD →

Listing, Classified Ads & Business Directory – uListing <= 2.0.5 - Reflected Cross-Site Scripting

medium

Authenticated Reflected Cross-Site Scripting (XSS) vulnerability in WordPress uListing plugin (versions <= 2.0.5). Vulnerable parameters: &filter[id], &filter[user], &filter[expired_date], &filter[created_date], &filter[updated_date].

CVSS:
6.1
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Jul 27, 2021

CVE-2021-36875 on NVD →

uListing plugin <= 2.0.5 - Authenticated Insecure Direct Object References (IDOR)

high

Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5).

CVSS:
7.1
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Jul 27, 2021

CVE-2021-36874 on NVD →

Listing, Classified Ads & Business Directory – uListing <= 2.0.3 - Unauthenticated SQL Injection

critical

Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom.

CVSS:
9.8
Affected:
up to 2.0.3
Fixed in:
2.0.4
Disclosed:
Jul 26, 2021

CVE-2021-36880 on NVD →

uListing <= 1.6.6 - Unauthenticated Arbitrary Account Changes

critical

The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible for unauthenticated attackers to edit any account on the blog, such as changing th...

CVSS:
9.8
Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

CVE-2021-4346 on NVD →

uListing <= 1.6.6 - Missing Authorization

critical

The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack security nonces, and data is seldom validated. This issue exists in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to conduct nu...

CVSS:
9.8
Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

CVE-2021-4370 on NVD →

uListing <= 1.6.6 - Unauthenticated Options Changes via wp_route

critical

The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout::import_new_layout method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any WordPre...

CVSS:
9.8
Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

CVE-2021-4381 on NVD →

uListing <= 1.6.6 - Unauthenticated Arbitrary Account Creation

critical

The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. This is due to the stm_listing_register AJAX action function being accessible and taking roles unprotected. This makes it possible for unauthenticated attackers to create...

CVSS:
9.8
Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

CVE-2021-4343 on NVD →

uListing <= 1.6.6 - Unauthenticated Wordpress Options Changes via AJAX

critical

The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm_update_email_data AJAX action in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any W...

CVSS:
9.8
Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

CVE-2021-4341 on NVD →

uListing <= 1.6.6 - Unauthenticated Arbitrary Post/Page Deletion

critical

The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to arbitrarily delete site posts and pages...

CVSS:
9.1
Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

CVE-2021-4357 on NVD →

uListing <= 1.6.6 - Unauthenticated Information Disclosure

high

The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file on the /1/api/ulisting-user/search REST-API route in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to retrieve the list of all...

CVSS:
7.5
Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

CVE-2021-4339 on NVD →

uListing <= 1.6.6 - Unauthenticated Arbitrary Roles and Capabilities Creation/Deletion

medium

The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on the UlistingUserRole::save_role_api method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to remove or add roles, and add capabilities.

CVSS:
6.5
Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

CVE-2021-4345 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack security nonces, and data is seldom validated. This issue exists in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to conduct nu...

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

Unauthenticated Information Disclosure vulnerability found by Jerome Bruandet in WordPress uListing plugin (versions <= 1.6.6).

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities found by Jerome Bruandet in WordPress uListing plugin (versions <= 1.6.6).

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

Unauthenticated Arbitrary Post/Page Deletion vulnerability found by Jerome Bruandet in WordPress uListing plugin (versions <= 1.6.6).

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

Unauthenticated Arbitrary Roles and Capabilities Creation/Deletion vulnerability found by Jerome Bruandet in WordPress uListing plugin (versions <= 1.6.6).

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

Unauthenticated Arbitrary Account Creation/Change vulnerability found by Jerome Bruandet in WordPress uListing plugin (versions <= 1.6.6).

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file on the /1/api/ulisting-user/search REST-API route in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to retrieve the list of all...

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm_update_email_data AJAX action in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any W...

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. This is due to the stm_listing_register AJAX action function being accessible and taking roles unprotected. This makes it possible for unauthenticated attackers to create...

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible for unauthenticated attackers to edit any account on the blog, such as changing th...

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on the UlistingUserRole::save_role_api method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to remove or add roles, and add capabilities.

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout::import_new_layout method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any WordPre...

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to arbitrarily delete site posts and pages...

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jan 28, 2021

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown
Affected:
up to 1.7
Fixed in:
1.7

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

The /1/api/ulisting-page-statistics/listing REST route did not sanitise or escape the listing_id and user_id GET parameters before using them in a SQL statement, leading to an SQL Injection issue. The plugin also did not sanitise and escape the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR which are then used in a SQL sta...

Affected:
up to 1.7
Fixed in:
1.7

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

The /1/api/ulisting-user/search REST route did not perform capability and CSRF checks, allowing unauthenticated users to get the list of all users and their email address.

Affected:
up to 1.7
Fixed in:
1.7

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

The /1/api/ulisting-user/role/save REST route did not perform capability and CSRF checks, allowing unauthenticated users to remove and add roles, as well as add capabilities to the blog.

Affected:
up to 1.7
Fixed in:
1.7

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

The /1/api/ulisting-user/deletelisting REST route did not have any authorisation and CSRF checks in place, allowing unauthenticated usesr to delete any page or post.

Affected:
up to 1.7
Fixed in:
1.7

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

The AJAX action stm_listing_register() accessible to both authenticated and unauthenticated users did not perform capability and CSRF checks, allowing an unauthenticated user to create arbitrary accounts on the blog, including administrator ones.

Affected:
up to 1.7
Fixed in:
1.7

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7

unknown

The AJAX action stm_listing_profile_edit() accessible to both authenticated and unauthenticated users did not perform capability and CSRF checks, and did not ensure that the edited account belonged to the user making the request. This allows unauthenticated users to update arbitrary accounts, such as changing their ema...

Affected:
up to 1.7
Fixed in:
1.7

Directory Listings WordPress plugin &#8211; uListing [ulisting] <= 2.2.0 (unfixed)

unknown
Affected:
up to 2.2.0
Fix:
No patched version reported

CVE-2025-1657 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] <= 2.2.0 (unfixed)

unknown
Affected:
up to 2.2.0
Fix:
No patched version reported

CVE-2025-1653 on NVD →

Directory Listings WordPress plugin &#8211; uListing [ulisting] < 2.0.9

unknown

The plugin does not have CSRF check in the uListing_import_layout function, nor perform any validation on the option/post meta key to update to ensure it belongs to the plugin. As a result, attackers could make a logged in admin change any of the blog option (such as siteurl, blogname etc) as well as post meta to arbit...

Affected:
up to 2.0.9
Fixed in:
2.0.9

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database