Stored Cross-Site Scripting in Ultimate Classified Listings Plugin for WordPress
CVE-2024-13748
4.8MEDIUM
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 20 February 2025
Summary
The Ultimate Classified Listings plugin for WordPress is susceptible to Stored Cross-Site Scripting attacks through the Title parameter. This vulnerability arises from inadequate sanitization of user inputs and lack of proper escaping of output in all versions up to and including 1.4. Authenticated attackers with administrator privileges can exploit this flaw, injecting malicious scripts into web pages viewed by users. The vulnerability specifically impacts multi-site installations and those where unfiltered_html is disabled, making it a significant risk for affected setups.
Affected Version(s)
Ultimate Classified Listings * <= 1.4
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nguyễn Văn Đạt