CVE-2021-36875: WordPress uListing plugin <= 2.0.5 - Auth. Reflected Cross-Site Scripting (XSS) vulnerability
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability in WordPress uListing plugin (versions <= 2.0.5). Vulnerable parameters: &filter[id], &filter[user], &filter[expireddate], &filter[createddate], &filter[updateddate].
Other sources
Cross-site Scripting (XSS) vulnerability in Stylemix Directory Listings WordPress plugin – uListing allows Reflected XSS.This issue affects Directory Listings WordPress plugin – uListing: from n/a through 2.0.5.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36875.
What is the title of the vulnerability?
The title of the vulnerability is Authenticated Reflected Cross-Site Scripting (XSS) vulnerability in WordPress uListing plugin (version <= 2.0.5).
What is the affected software?
The affected software is the uListing plugin for WordPress (versions <= 2.0.5) by Stylemixthemes.
What is the severity of the vulnerability?
The severity of the vulnerability is medium with a CVSS score of 4.8.
How do I fix the vulnerability?
To fix the vulnerability, you should update the uListing plugin to the latest version (2.0.6 or higher) provided by the plugin developer.