Access violation vulnerability in Directory Listings WordPress plugin – uListing 1.7

The uListing plugin for WordPress is not secure in versions 1.6.6 and earlier. A malicious user can potentially bypass the authorization process and change any WordPress option in the database without being authenticated. This is because the plugin is missing capability checks, input validation, and a security nonce in the stm_update_email_data AJAX action.

Detected in:

Directory Listings WordPress plugin – uListing open vulnerable versions: >= * < 1.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.