cleantalk
Vulnerabilities and Security Researches

Directory Listings WordPress plugin – uListing, CVE-2021-36875

CVE, Research URL

CVE-2021-36875

Published on
Sep 27, 2021
Research Description
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability in WordPress uListing plugin (versions <= 2.0.5). Vulnerable parameters: &filter[id], &filter[user], &filter[expired_date], &filter[created_date], &filter[updated_date].
Affected versions
Min -, max 2.0.6.
Status
vulnerable