VYPR

Ultimate Classified Listings

by Webcodingplace

Source repositories

CVEs (5)

  • CVE-2024-5882HigJul 29, 2024
    risk 0.49cvss 7.5epss 0.01

    The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page

  • CVE-2024-13753HigFeb 20, 2025
    risk 0.46cvss 8.1epss 0.00

    The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the update_profile function. This makes it possible for unauthenticated attackers…

  • CVE-2024-6529HigAug 1, 2024
    risk 0.46cvss 7.1epss 0.01

    The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2024-5883MedJul 29, 2024
    risk 0.31cvss 4.7epss 0.00

    The Ultimate Classified Listings WordPress plugin before 1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2024-13748MedFeb 20, 2025
    risk 0.29cvss 4.4epss 0.00

    The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title parameter in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…