CVE-2024-5882: Ultimate Classified Listings < 1.3 - Unauthenticated LFI
The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the uclpage and layout parameters allowing unauthenticated users to access PHP files on the server from the listings page
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5882?
CVE-2024-5882 is rated as a high-severity vulnerability due to its potential for unauthenticated access to sensitive PHP files.
How do I fix CVE-2024-5882?
To fix CVE-2024-5882, upgrade the Ultimate Classified Listings WordPress plugin to version 1.3 or later.
Who is affected by CVE-2024-5882?
CVE-2024-5882 affects users of the Ultimate Classified Listings WordPress plugin versions prior to 1.3.
What types of attacks can exploit CVE-2024-5882?
CVE-2024-5882 can be exploited by attackers to gain unauthorized access to PHP files, potentially leading to further compromise of the site.
Is authentication required to exploit CVE-2024-5882?
No, CVE-2024-5882 can be exploited by unauthenticated users, making it particularly dangerous.