CVE-2021-36880: WordPress uListing plugin <= 2.0.3 - Unauthenticated SQL Injection (SQLi) vulnerability
Published Sep 27, 2021
·Updated
Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom.
Affected Software
1 affected component
StylemixThemes Ulisting Wordpress<=2.0.3
Remediation
Information
Update to 2.0.4 or higher version.
Event History
Sep 27, 2021
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-36880?
The severity of CVE-2021-36880 is critical with a CVSS score of 9.8.
2
Which software versions are affected by CVE-2021-36880?
Versions of the uListing plugin up to and including 2.0.3 are affected by CVE-2021-36880.
3
What is the vulnerability in WordPress uListing plugin?
CVE-2021-36880 is an unauthenticated SQL Injection (SQLi) vulnerability in the WordPress uListing plugin.
4
What is the vulnerable parameter in CVE-2021-36880?
The vulnerable parameter in CVE-2021-36880 is 'custom'.
5
How can I fix CVE-2021-36880 in WordPress uListing plugin?
To fix CVE-2021-36880 in the WordPress uListing plugin, update to a version higher than 2.0.3.