First published: Tue Jul 27 2021(Updated: )
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability in WordPress uListing plugin (versions <= 2.0.5). Vulnerable parameters: &filter[id], &filter[user], &filter[expired_date], &filter[created_date], &filter[updated_date].
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Stylemixthemes Ulisting | <=2.0.5 |
Update to 2.0.6 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-36875.
The title of the vulnerability is Authenticated Reflected Cross-Site Scripting (XSS) vulnerability in WordPress uListing plugin (version <= 2.0.5).
The affected software is the uListing plugin for WordPress (versions <= 2.0.5) by Stylemixthemes.
The severity of the vulnerability is medium with a CVSS score of 4.8.
To fix the vulnerability, you should update the uListing plugin to the latest version (2.0.6 or higher) provided by the plugin developer.