Ultimate Classified Listings <= 1.6 - Authenticated (Contributor+) Local File Inclusion
high
The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6 via the 'uclwp_dashboard' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the serve...
- CVSS:
- 7.5
- Affected:
- up to 1.6
- Fixed in:
- 1.7
- Disclosed:
- Sep 10, 2025
CVE-2025-9874 on NVD →
Ultimate Classified Listings <= 1.7 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update
medium
The Ultimate Classified Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_custom_fields function in all versions up to, and including, 1.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change p...
- CVSS:
- 4.3
- Affected:
- up to 1.7
- Fix:
- No patched version reported
- Disclosed:
- Sep 10, 2025
CVE-2025-0763 on NVD →
Ultimate Classified Listings [ultimate-classified-listings] < 1.5
unknown
[en] The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title parameter in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to in...
- Affected:
- up to 1.5
- Fixed in:
- 1.5
- Disclosed:
- Feb 20, 2025
CVE-2024-13748 on NVD →
Ultimate Classified Listings [ultimate-classified-listings] < 1.6
unknown
[en] The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the update_profile function. This makes it possible for unauthenticated attackers to modify victim's email via a forge...
- Affected:
- up to 1.6
- Fixed in:
- 1.6
- Disclosed:
- Feb 20, 2025
CVE-2024-13753 on NVD →
Ultimate Classified Listings <= 1.4 Authenticated (Administrator+) Stored Cross-Site Scripting via Title Parameter
medium
The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title parameter in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject...
- CVSS:
- 4.4
- Affected:
- up to 1.4
- Fixed in:
- 1.5
- Disclosed:
- Feb 19, 2025
CVE-2024-13748 on NVD →
Ultimate Classified Listings <= 1.5 - Cross-Site Request Forgery to Account Takeover
high
The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the update_profile function. This makes it possible for unauthenticated attackers to modify victim's email via a forged req...
- CVSS:
- 8.1
- Affected:
- up to 1.5
- Fixed in:
- 1.6
- Disclosed:
- Feb 19, 2025
CVE-2024-13753 on NVD →
Ultimate Classified Listings [ultimate-classified-listings] <= 1.6 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Ultimate Classified Listings allows Stored XSS.This issue affects Ultimate Classified Listings: from n/a through 1.4.
- Affected:
- up to 1.6
- Fix:
- No patched version reported
- Disclosed:
- Dec 2, 2024
CVE-2024-52487 on NVD →
Ultimate Classified Listings [ultimate-classified-listings] <= 1.6 (unfixed)
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebCodingPlace Ultimate Classified Listings allows PHP Local File Inclusion.This issue affects Ultimate Classified Listings: from n/a through 1.4.
- Affected:
- up to 1.6
- Fix:
- No patched version reported
- Disclosed:
- Nov 20, 2024
CVE-2024-52448 on NVD →
Ultimate Classified Listings <= 1.7 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 1.7
- Fixed in:
- 2.0
- Disclosed:
- Nov 19, 2024
CVE-2024-52487 on NVD →
Ultimate Classified Listings <= 1.7 - Authenticated (Contributor+) Local File Inclusion
high
The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in...
- CVSS:
- 8.8
- Affected:
- up to 1.7
- Fixed in:
- 2.0
- Disclosed:
- Nov 18, 2024
CVE-2024-52448 on NVD →
Ultimate Classified Listings [ultimate-classified-listings] < 1.4
unknown
[en] The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 1.4
- Fixed in:
- 1.4
- Disclosed:
- Aug 1, 2024
CVE-2024-6529 on NVD →
Ultimate Classified Listings [ultimate-classified-listings] < 1.3
unknown
[en] The Ultimate Classified Listings WordPress plugin before 1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 1.3
- Fixed in:
- 1.3
- Disclosed:
- Jul 29, 2024
CVE-2024-5883 on NVD →
Ultimate Classified Listings [ultimate-classified-listings] < 1.4
unknown
[en] The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page
- Affected:
- up to 1.4
- Fixed in:
- 1.4
- Disclosed:
- Jul 29, 2024
CVE-2024-5882 on NVD →
Ultimate Classified Listings <= 1.3 - Reflected Cross-Site Scripting
medium
The Ultimate Classified Listings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they c...
- CVSS:
- 6.1
- Affected:
- up to 1.3
- Fixed in:
- 1.4
- Disclosed:
- Jul 11, 2024
CVE-2024-6529 on NVD →
Ultimate Classified Listings <= 1.2 - Reflected Cross-Site Scripting
medium
The Ultimate Classified Listings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they c...
- CVSS:
- 6.1
- Affected:
- up to 1.2
- Fixed in:
- 1.3
- Disclosed:
- Jul 8, 2024
CVE-2024-5883 on NVD →
Ultimate Classified Listings <= 1.3 - Unauthenticated Local File Inclusion
medium
The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3 via the 'ucl_page' and 'layout' parameters. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP c...
- CVSS:
- 6.1
- Affected:
- up to 1.3
- Fixed in:
- 1.4
- Disclosed:
- Jul 8, 2024
CVE-2024-5882 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database