Search Results (22 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-4381 1 Stylemixthemes 1 Ulisting 2024-12-28 9.8 Critical
The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout::import_new_layout method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any WordPress option in the database.
CVE-2024-47344 1 Stylemixthemes 1 Ulisting 2024-10-07 5.3 Medium
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StylemixThemes uListing.This issue affects uListing: from n/a through 2.1.5.