📦 Ulisting

by Stylemixthemes

🔍 What is Ulisting?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-4381

CRITICAL CVSS 9.8 Jun 7, 2023

The uListing WordPress plugin up to version 1.6.6 has an authorization bypass vulnerability that allows unauthenticated attackers to modify any WordPress option in the database. This occurs due to mis...

CVE-2021-4370

CRITICAL CVSS 9.8 Jun 7, 2023

The uListing WordPress plugin up to version 1.6.6 has an authorization bypass vulnerability where unauthenticated users can access administrative actions and endpoints. This occurs due to missing secu...

CVE-2021-4340

CRITICAL CVSS 9.8 Jun 7, 2023

The uListing WordPress plugin contains an SQL injection vulnerability in versions up to 1.6.6 that allows unauthenticated attackers to execute arbitrary SQL queries. This can lead to data theft, inclu...

CVE-2021-4343

CRITICAL CVSS 9.8 Jun 7, 2023

This vulnerability in the Unauthenticated Account Creation plugin for WordPress allows unauthenticated attackers to create user accounts, including administrator accounts, without any authentication. ...

CVE-2021-4346

CRITICAL CVSS 9.8 Jun 7, 2023

The uListing WordPress plugin up to version 1.6.6 has an authentication bypass vulnerability that allows unauthenticated attackers to modify any user account, including administrators. This occurs bec...

CVE-2021-36879

CRITICAL CVSS 9.8 Sep 27, 2021

This vulnerability allows unauthenticated attackers to escalate privileges in WordPress sites using the uListing plugin (versions 2.0.5 and earlier). Attackers can gain administrative access without c...

CVE-2025-1653

HIGH CVSS 8.8 Mar 15, 2025

The uListing WordPress plugin has a privilege escalation vulnerability that allows authenticated users with Subscriber-level access or higher to elevate their privileges to administrator. This occurs ...

CVE-2025-1657

HIGH CVSS 8.8 Mar 15, 2025

The uListing WordPress plugin has a vulnerability that allows authenticated attackers with subscriber-level access or higher to modify post metadata and inject PHP objects through AJAX requests. This ...

CVE-2021-4339

HIGH CVSS 7.5 Jun 7, 2023

The uListing WordPress plugin up to version 1.6.6 has an authorization bypass vulnerability in its REST API endpoint. Unauthenticated attackers can exploit this to retrieve all user data including ema...

CVE-2021-36874

HIGH CVSS 7.1 Sep 27, 2021

This vulnerability allows authenticated WordPress users to access or modify data belonging to other users through insecure direct object references in the uListing plugin. It affects WordPress sites r...