Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization
medium
The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized act...
- CVSS:
- 4.3
- Affected:
- up to 2.2.0
- Fix:
- No patched version reported
- Disclosed:
- Jul 22, 2026
CVE-2026-27391 on NVD →
Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization
medium
The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized ac...
- CVSS:
- 4.3
- Affected:
- up to 2.2.0
- Fix:
- No patched version reported
- Disclosed:
- Jul 22, 2026
CVE-2026-27392 on NVD →
uListing - Arbitrary File Download vulnerability
medium
Arbitrary File Download vulnerability
- CVSS:
- 4.9
- Affected:
- up to 2.2.0
- Fix:
- No patched version reported
- Disclosed:
- Feb 26, 2026
Directory Listings WordPress plugin – uListing <= 2.2.0 - Authenticated (Editor+) Arbitrary File Download
medium
The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with Editor-level access and above, to read the contents of arbitrary files on the server, which can contain sensi...
- CVSS:
- 4.9
- Affected:
- up to 2.2.0
- Fix:
- No patched version reported
- Disclosed:
- Feb 26, 2026
CVE-2026-28078 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] <= 2.2.0 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects uListing: from n/a through <= 2.2.0.
- Affected:
- up to 2.2.0
- Fix:
- No patched version reported
- Disclosed:
- Feb 26, 2026
CVE-2026-28138 on NVD →
uListing <= 2.2.0 - Authenticated (Administrator+) PHP Object Injection
medium
The uListing plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable s...
- CVSS:
- 6.6
- Affected:
- up to 2.2.0
- Fix:
- No patched version reported
- Disclosed:
- Apr 22, 2025
CVE-2026-28138 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] <= 2.2.0 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in Stylemix uListing allows Object Injection. This issue affects uListing: from n/a through 2.2.0.
- Affected:
- up to 2.2.0
- Fix:
- No patched version reported
- Disclosed:
- Apr 17, 2025
CVE-2025-32662 on NVD →
uListing <= 2.2.0 - Authenticated (Subscriber+) PHP Object Injection
high
The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known P...
- CVSS:
- 8.8
- Affected:
- up to 2.2.0
- Fix:
- No patched version reported
- Disclosed:
- Apr 15, 2025
CVE-2025-32662 on NVD →
uListing <= 2.1.9 - Authenticated (Administrator+) SQL Injection
medium
The uListing plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and abov...
- CVSS:
- 4.9
- Affected:
- up to 2.1.9
- Fix:
- No patched version reported
- Disclosed:
- Apr 4, 2025
CVE-2025-32122 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] <= 2.2.0 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing allows Blind SQL Injection. This issue affects uListing: from n/a through 2.1.9.
- Affected:
- up to 2.2.0
- Fix:
- No patched version reported
- Disclosed:
- Apr 4, 2025
CVE-2025-32122 on NVD →
Directory Listings WordPress plugin – uListing <= 2.2.0 - Authenticated (Subscriber+) Privilege Escalation
high
The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.0. This is due to the stm_listing_profile_edit AJAX action not having enough restriction on the user meta that can be updated. This makes it possible for authenticated...
- CVSS:
- 8.8
- Affected:
- up to 2.2.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 14, 2025
CVE-2025-1653 on NVD →
Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Update and PHP Object Injection
high
The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized modification of data and PHP Object Injection due to a missing capability check on the stm_listing_ajax AJAX action in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with...
- CVSS:
- 8.8
- Affected:
- up to 2.2.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 14, 2025
CVE-2025-1657 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 2.1.7
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing allows Blind SQL Injection. This issue affects uListing: from n/a through 2.1.6.
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.7
- Disclosed:
- Mar 3, 2025
CVE-2025-25150 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 2.1.7
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes uListing allows SQL Injection. This issue affects uListing: from n/a through 2.1.6.
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.7
- Disclosed:
- Feb 7, 2025
CVE-2025-25151 on NVD →
uListing <= 2.1.6 - Unauthenticated SQL Injection
high
The uListing plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into a...
- CVSS:
- 7.5
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.7
- Disclosed:
- Feb 3, 2025
CVE-2025-25150 on NVD →
uListing <= 2.1.6 - Authenticated (Contributor+) SQL Injection
medium
The uListing plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above,...
- CVSS:
- 6.5
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.7
- Disclosed:
- Feb 3, 2025
CVE-2025-25151 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 2.1.6
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StylemixThemes uListing.This issue affects uListing: from n/a through 2.1.5.
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.6
- Disclosed:
- Oct 7, 2024
CVE-2024-47344 on NVD →
uListing <= 2.1.5 - Unauthenticated Information Exposure
medium
The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.5 via the /pricing-plan/payment endpoint. This makes it possible for unauthenticated attackers to render the pricing plan payment page.
- CVSS:
- 5.3
- Affected:
- up to 2.1.5
- Fixed in:
- 2.1.6
- Disclosed:
- Sep 27, 2024
CVE-2024-47344 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
[en] The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible for unauthenticated attackers to edit any account on the blog, such as changi...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jun 7, 2023
CVE-2021-4346 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
[en] The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout::import_new_layout method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any Wo...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jun 7, 2023
CVE-2021-4381 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
[en] The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack security nonces, and data is seldom validated. This issue exists in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to condu...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jun 7, 2023
CVE-2021-4370 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
[en] The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jun 7, 2023
CVE-2021-4340 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
[en] The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. This is due to the stm_listing_register AJAX action function being accessible and taking roles unprotected. This makes it possible for unauthenticated attackers to cr...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jun 7, 2023
CVE-2021-4343 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
[en] The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on the UlistingUserRole::save_role_api method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to remove or add roles, and add capabilities.
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jun 7, 2023
CVE-2021-4345 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
[en] The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to arbitrarily delete site posts and...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jun 7, 2023
CVE-2021-4357 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
[en] The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm_update_email_data AJAX action in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jun 7, 2023
CVE-2021-4341 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
[en] The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file on the /1/api/ulisting-user/search REST-API route in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to retrieve the list of...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jun 7, 2023
CVE-2021-4339 on NVD →
uListing <= 1.6.6 - Unauthenticated SQL Injection
critical
The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers...
- CVSS:
- 9.8
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Oct 28, 2021
CVE-2021-4340 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Oct 28, 2021
Directory Listings WordPress plugin – uListing [ulisting] < 2.0.4
unknown
[en] Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom.
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- Sep 27, 2021
CVE-2021-36880 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 2.0.6
unknown
[en] Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration.
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Sep 27, 2021
CVE-2021-36879 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 2.0.6
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles.
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Sep 27, 2021
CVE-2021-36877 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 2.0.6
unknown
[en] Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks CSRF checks on plugin administration pages.
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Sep 27, 2021
CVE-2021-36876 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 2.0.6
unknown
[en] Cross-site Scripting (XSS) vulnerability in Stylemix Directory Listings WordPress plugin – uListing allows Reflected XSS.This issue affects Directory Listings WordPress plugin – uListing: from n/a through 2.0.5.
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Sep 27, 2021
CVE-2021-36875 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 2.0.6
unknown
[en] Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5).
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Sep 27, 2021
CVE-2021-36874 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 2.0.6
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings.
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Sep 27, 2021
CVE-2021-36878 on NVD →
Listing, Classified Ads & Business Directory – uListing <= 2.0.8 - Cross-Site Request Forgery
high
The Listing, Classified Ads & Business Directory – uListing plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.8. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to edit blog settings and...
- CVSS:
- 8.8
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.9
- Disclosed:
- Sep 6, 2021
Directory Listings WordPress plugin – uListing [ulisting] < 2.0.9
unknown
The Listing, Classified Ads & Business Directory – uListing plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.8. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to edit blog settings and...
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.9
- Disclosed:
- Sep 6, 2021
Listing, Classified Ads & Business Directory – uListing <= 2.0.5 - Privilege Escalation
critical
Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration.
- CVSS:
- 9.8
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Jul 27, 2021
CVE-2021-36879 on NVD →
uListing <= 2.0.5 - Cross-Site Request Forgery leading to Settings Change
medium
The Cross-Site Request Forgery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to make changes to the plugin's settings via forged request granted they can trick a site administrator into performing an action...
- CVSS:
- 4.3
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Jul 27, 2021
CVE-2021-36878 on NVD →
Listing, Classified Ads & Business Directory – uListing <= 2.0.5 - Cross-Site Request Forgery
medium
Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles.
- CVSS:
- 6.5
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Jul 27, 2021
CVE-2021-36877 on NVD →
Listing, Classified Ads & Business Directory – uListing <= 2.0.5 - Cross-Site Request Forgery
medium
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks CSRF checks on plugin administration pages.
- CVSS:
- 5.4
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Jul 27, 2021
CVE-2021-36876 on NVD →
Listing, Classified Ads & Business Directory – uListing <= 2.0.5 - Reflected Cross-Site Scripting
medium
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability in WordPress uListing plugin (versions <= 2.0.5). Vulnerable parameters: &filter[id], &filter[user], &filter[expired_date], &filter[created_date], &filter[updated_date].
- CVSS:
- 6.1
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Jul 27, 2021
CVE-2021-36875 on NVD →
uListing plugin <= 2.0.5 - Authenticated Insecure Direct Object References (IDOR)
high
Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5).
- CVSS:
- 7.1
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Jul 27, 2021
CVE-2021-36874 on NVD →
Listing, Classified Ads & Business Directory – uListing <= 2.0.3 - Unauthenticated SQL Injection
critical
Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom.
- CVSS:
- 9.8
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- Jul 26, 2021
CVE-2021-36880 on NVD →
uListing <= 1.6.6 - Unauthenticated Arbitrary Account Changes
critical
The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible for unauthenticated attackers to edit any account on the blog, such as changing th...
- CVSS:
- 9.8
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
CVE-2021-4346 on NVD →
uListing <= 1.6.6 - Missing Authorization
critical
The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack security nonces, and data is seldom validated. This issue exists in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to conduct nu...
- CVSS:
- 9.8
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
CVE-2021-4370 on NVD →
uListing <= 1.6.6 - Unauthenticated Options Changes via wp_route
critical
The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout::import_new_layout method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any WordPre...
- CVSS:
- 9.8
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
CVE-2021-4381 on NVD →
uListing <= 1.6.6 - Unauthenticated Arbitrary Account Creation
critical
The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. This is due to the stm_listing_register AJAX action function being accessible and taking roles unprotected. This makes it possible for unauthenticated attackers to create...
- CVSS:
- 9.8
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
CVE-2021-4343 on NVD →
uListing <= 1.6.6 - Unauthenticated Wordpress Options Changes via AJAX
critical
The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm_update_email_data AJAX action in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any W...
- CVSS:
- 9.8
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
CVE-2021-4341 on NVD →
uListing <= 1.6.6 - Unauthenticated Arbitrary Post/Page Deletion
critical
The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to arbitrarily delete site posts and pages...
- CVSS:
- 9.1
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
CVE-2021-4357 on NVD →
uListing <= 1.6.6 - Unauthenticated Information Disclosure
high
The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file on the /1/api/ulisting-user/search REST-API route in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to retrieve the list of all...
- CVSS:
- 7.5
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
CVE-2021-4339 on NVD →
uListing <= 1.6.6 - Unauthenticated Arbitrary Roles and Capabilities Creation/Deletion
medium
The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on the UlistingUserRole::save_role_api method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to remove or add roles, and add capabilities.
- CVSS:
- 6.5
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
CVE-2021-4345 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack security nonces, and data is seldom validated. This issue exists in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to conduct nu...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
Unauthenticated Information Disclosure vulnerability found by Jerome Bruandet in WordPress uListing plugin (versions <= 1.6.6).
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities found by Jerome Bruandet in WordPress uListing plugin (versions <= 1.6.6).
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
Unauthenticated Arbitrary Post/Page Deletion vulnerability found by Jerome Bruandet in WordPress uListing plugin (versions <= 1.6.6).
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
Unauthenticated Arbitrary Roles and Capabilities Creation/Deletion vulnerability found by Jerome Bruandet in WordPress uListing plugin (versions <= 1.6.6).
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
Unauthenticated Arbitrary Account Creation/Change vulnerability found by Jerome Bruandet in WordPress uListing plugin (versions <= 1.6.6).
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file on the /1/api/ulisting-user/search REST-API route in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to retrieve the list of all...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm_update_email_data AJAX action in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any W...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. This is due to the stm_listing_register AJAX action function being accessible and taking roles unprotected. This makes it possible for unauthenticated attackers to create...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible for unauthenticated attackers to edit any account on the blog, such as changing th...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on the UlistingUserRole::save_role_api method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to remove or add roles, and add capabilities.
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout::import_new_layout method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any WordPre...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to arbitrarily delete site posts and pages...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
- Disclosed:
- Jan 28, 2021
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
- Affected:
- up to 1.7
- Fixed in:
- 1.7
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
The /1/api/ulisting-page-statistics/listing REST route did not sanitise or escape the listing_id and user_id GET parameters before using them in a SQL statement, leading to an SQL Injection issue.
The plugin also did not sanitise and escape the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR which are then used in a SQL sta...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
The /1/api/ulisting-user/search REST route did not perform capability and CSRF checks, allowing unauthenticated users to get the list of all users and their email address.
- Affected:
- up to 1.7
- Fixed in:
- 1.7
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
The /1/api/ulisting-user/role/save REST route did not perform capability and CSRF checks, allowing unauthenticated users to remove and add roles, as well as add capabilities to the blog.
- Affected:
- up to 1.7
- Fixed in:
- 1.7
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
The /1/api/ulisting-user/deletelisting REST route did not have any authorisation and CSRF checks in place, allowing unauthenticated usesr to delete any page or post.
- Affected:
- up to 1.7
- Fixed in:
- 1.7
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
The AJAX action stm_listing_register() accessible to both authenticated and unauthenticated users did not perform capability and CSRF checks, allowing an unauthenticated user to create arbitrary accounts on the blog, including administrator ones.
- Affected:
- up to 1.7
- Fixed in:
- 1.7
Directory Listings WordPress plugin – uListing [ulisting] < 1.7
unknown
The AJAX action stm_listing_profile_edit() accessible to both authenticated and unauthenticated users did not perform capability and CSRF checks, and did not ensure that the edited account belonged to the user making the request. This allows unauthenticated users to update arbitrary accounts, such as changing their ema...
- Affected:
- up to 1.7
- Fixed in:
- 1.7
Directory Listings WordPress plugin – uListing [ulisting] <= 2.2.0 (unfixed)
unknown
- Affected:
- up to 2.2.0
- Fix:
- No patched version reported
CVE-2025-1657 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] <= 2.2.0 (unfixed)
unknown
- Affected:
- up to 2.2.0
- Fix:
- No patched version reported
CVE-2025-1653 on NVD →
Directory Listings WordPress plugin – uListing [ulisting] < 2.0.9
unknown
The plugin does not have CSRF check in the uListing_import_layout function, nor perform any validation on the option/post meta key to update to ensure it belongs to the plugin. As a result, attackers could make a logged in admin change any of the blog option (such as siteurl, blogname etc) as well as post meta to arbit...
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.9