CVE-2021-4341
- EPSS 0.2%
- Veröffentlicht 07.06.2023 02:15:13
- Zuletzt bearbeitet 21.11.2024 06:37:27
The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm_update_email_data AJAX action in versions up to, and including, 1.6.6...
CVE-2021-4340
- EPSS 0.71%
- Veröffentlicht 07.06.2023 02:15:13
- Zuletzt bearbeitet 21.11.2024 06:37:27
The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exis...
CVE-2021-4339
- EPSS 0.66%
- Veröffentlicht 07.06.2023 02:15:13
- Zuletzt bearbeitet 21.11.2024 06:37:27
The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file on the /1/api/ulisting-user/search REST-API route in versions up to, and including, 1.6.6. This makes ...
CVE-2021-36880
- EPSS 4.73%
- Veröffentlicht 27.09.2021 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:14:14
Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom.
CVE-2021-36879
- EPSS 0.53%
- Veröffentlicht 27.09.2021 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:14:14
Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration.
CVE-2021-36877
- EPSS 0.1%
- Veröffentlicht 27.09.2021 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:14:14
Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles.
CVE-2021-36876
- EPSS 0.11%
- Veröffentlicht 27.09.2021 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:14:14
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks CSRF checks on plugin administration pages.
CVE-2021-36875
- EPSS 0.26%
- Veröffentlicht 27.09.2021 16:15:09
- Zuletzt bearbeitet 01.07.2025 21:15:25
Cross-site Scripting (XSS) vulnerability in Stylemix Directory Listings WordPress plugin – uListing allows Reflected XSS.This issue affects Directory Listings WordPress plugin – uListing: from n/a through 2.0.5.
CVE-2021-36874
- EPSS 1.01%
- Veröffentlicht 27.09.2021 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:14:14
Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5).
CVE-2021-36878
- EPSS 0.1%
- Veröffentlicht 27.09.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:14:14
Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings.