High severity7.5NVD Advisory· Published Jul 29, 2024· Updated Jun 17, 2026
CVE-2024-5882
CVE-2024-5882
Description
The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the ucl_page and layout parameters allowing unauthenticated users to access PHP files on the server from the listings page
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:webcodingplace:ultimate_classified_listings:*:*:*:*:*:wordpress:*:*Range: <1.3
(expand)+ 1 more
- (no CPE)
- (no CPE)range: <1.3
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/5e8d7808-8f3e-4fc9-a1e7-e108da031ca7/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.