First published: Mon Sep 27 2021(Updated: )
Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Stylemixthemes Ulisting | <=2.0.3 |
Update to 2.0.4 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-36880 is critical with a CVSS score of 9.8.
Versions of the uListing plugin up to and including 2.0.3 are affected by CVE-2021-36880.
CVE-2021-36880 is an unauthenticated SQL Injection (SQLi) vulnerability in the WordPress uListing plugin.
The vulnerable parameter in CVE-2021-36880 is 'custom'.
To fix CVE-2021-36880 in the WordPress uListing plugin, update to a version higher than 2.0.3.