CVE-2026-28078
Directory Listings WordPress plugin – uListing
Minimum safe version
2.1.7
Update to 2.1.7 or later to address 42 fixable vulnerabilities
CVE-2026-28138
WordPress uListing plugin <= 2.2.0 - Deserialization of untrusted data vulnerability
WordPress uListing plugin <= 2.2.0 - SQL Injection vulnerability
Directory Listings WordPress plugin – uListing <= 2.2.0 - Authenticated (Subscriber+) Privilege Escalation
Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Update and PHP Object Injection
CVE-2025-25150
CVE-2025-25151
CVE-2024-47344
CVE-2021-4381
CVE-2021-4370
CVE-2021-4340
CVE-2021-4343
CVE-2021-4345
CVE-2021-4357
CVE-2021-4341
CVE-2021-4339
CVE-2021-4346
uListing <= 1.6.6 - Unauthenticated Options Changes via wp_route
uListing <= 1.6.6 - Missing Authorization
uListing <= 1.6.6 - Unauthenticated Arbitrary Post/Page Deletion
uListing <= 1.6.6 - Unauthenticated Arbitrary Roles and Capabilities Creation/Deletion
uListing <= 1.6.6 - Unauthenticated Arbitrary Account Changes
uListing <= 1.6.6 - Unauthenticated Arbitrary Account Creation
uListing <= 1.6.6 - Unauthenticated Wordpress Options Changes via AJAX
uListing <= 1.6.6 - Unauthenticated Information Disclosure
Listing, Classified Ads & Business Directory – uListing <= 2.0.8 - Cross-Site Request Forgery
uListing <= 1.6.6 - Unauthenticated SQL Injection
wpscan.com
uListing < 1.7 - Unauthenticated SQL Injections
uListing < 1.7 - Unauthenticated Information Disclosure
uListing < 1.7 - Unauthenticated Arbitrary Roles and Capabilities Creation/Deletion
uListing < 1.7 - Unauthenticated Arbitrary Post/Page Deletion
uListing < 1.7 - Unauthenticated Arbitrary Account Creation
uListing < 1.7 - Unauthenticated Arbitrary Account Change
uListing < 2.0.9 - Arbitrary Blog Option Update via CSRF
WordPress uListing plugin <= 1.6.6 - Unauthenticated Arbitrary Account Creation/Change vulnerability
WordPress uListing plugin <= 1.6.6 - Unauthenticated Arbitrary Roles and Capabilities Creation/Deletion vulnerability
WordPress uListing plugin <= 1.6.6 - Unauthenticated Arbitrary Post/Page Deletion vulnerability
WordPress uListing plugin <= 1.6.6 - Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities
WordPress uListing plugin <= 1.6.6 - Unauthenticated Information Disclosure vulnerability
CVE-2021-36880
CVE-2021-36879
CVE-2021-36878
CVE-2021-36877
CVE-2021-36876
CVE-2021-36875
CVE-2021-36874