Stored Cross-Site Scripting in Ultimate Classified Listings Plugin for WordPress
CVE-2024-13748

4.8MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
20 February 2025

Summary

The Ultimate Classified Listings plugin for WordPress is susceptible to Stored Cross-Site Scripting attacks through the Title parameter. This vulnerability arises from inadequate sanitization of user inputs and lack of proper escaping of output in all versions up to and including 1.4. Authenticated attackers with administrator privileges can exploit this flaw, injecting malicious scripts into web pages viewed by users. The vulnerability specifically impacts multi-site installations and those where unfiltered_html is disabled, making it a significant risk for affected setups.

Affected Version(s)

Ultimate Classified Listings * <= 1.4

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyễn Văn Đạt
.