Stored Cross-Site Scripting in Ultimate Classified Listings Plugin for WordPress
CVE-2024-13748
4.8MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 February 2025
What is CVE-2024-13748?
The Ultimate Classified Listings plugin for WordPress is susceptible to Stored Cross-Site Scripting attacks through the Title parameter. This vulnerability arises from inadequate sanitization of user inputs and lack of proper escaping of output in all versions up to and including 1.4. Authenticated attackers with administrator privileges can exploit this flaw, injecting malicious scripts into web pages viewed by users. The vulnerability specifically impacts multi-site installations and those where unfiltered_html is disabled, making it a significant risk for affected setups.
Affected Version(s)
Ultimate Classified Listings * <= 1.4