Directory Listings WordPress plugin – uListing, f53b1c0f-43c5-4bc4-b5e7-e286c15f6f2e
- CVE, Research URL
- Published on
- -
- Research Description
- Directory Listings WordPress plugin – uListing [ulisting] < 1.7 uListing < 1.7 - Unauthenticated Arbitrary Post/Page Deletion The /1/api/ulisting-user/deletelisting REST route did not have any authorisation and CSRF checks in place, allowing unauthenticated usesr to delete any page or post.
- Affected versions
-
max 1.7.
- Status
-
vulnerable