Extension WordPress
Vulnérabilités Directory Listings WordPress plugin – uListing, page 2
Cette page rassemble les failles publiées pour Directory Listings WordPress plugin – uListing, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Directory Listings WordPress plugin – uListing
26 fiches
uListing <= 1.6.6 – Unauthenticated Arbitrary Post/Page Deletion
The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers…
[*, 1.7)
1.7
28/01/2021
uListing <= 1.6.6 – Unauthenticated Arbitrary Roles and Capabilities Creation/Deletion
The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on the UlistingUserRole::save_role_api method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to remove or…
[*, 1.7)
1.7
28/01/2021
uListing <= 1.6.6 – Unauthenticated Arbitrary Account Changes
The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible for unauthenticated attackers…
[*, 1.7)
1.7
28/01/2021
uListing <= 1.6.6 – Unauthenticated Arbitrary Account Creation
The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. This is due to the stm_listing_register AJAX action function being accessible and taking roles unprotected. This makes it…
[*, 1.7)
1.7
28/01/2021
uListing <= 1.6.6 – Unauthenticated Wordpress Options Changes via AJAX
The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm_update_email_data AJAX action in versions up to, and including, 1.6.6. This…
[*, 1.7)
1.7
28/01/2021
uListing <= 1.6.6 – Unauthenticated Information Disclosure
The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file on the /1/api/ulisting-user/search REST-API route in versions up to, and including, 1.6.6. This makes it possible for unauthenticated…
[*, 1.7)
1.7
28/01/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.