Access violation vulnerability in Directory Listings WordPress plugin – uListing 1.7

The Unauthenticated Account Creation plugin for WordPress has a security vulnerability that allows hackers to create accounts on the WordPress website, even if the account has administrator privileges. This vulnerability affects versions up to and including 1.6.6 of the plugin. The vulnerability is caused by the stm_listing_register AJAX action function being unprotected, which allows attackers to create accounts without any authentication.

Detected in:

Directory Listings WordPress plugin – uListing open vulnerable versions: >= * < 1.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.