cleantalk
Vulnerabilities and Security Researches

Directory Listings WordPress plugin – uListing, CVE-2026-28138

CVE, Research URL

CVE-2026-28138

Published on
Feb 26, 2026
Research Description
Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects uListing: from n/a through <= 2.2.0.
Affected versions
max 2.2.0.
Status
vulnerable