CVE-2024-5883: Ultimate Classified Listings < 1.3 - Reflected XSS
The Ultimate Classified Listings WordPress plugin before 1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5883?
CVE-2024-5883 has a medium severity level due to its potential for Reflected Cross-Site Scripting affecting high privilege users.
How do I fix CVE-2024-5883?
To fix CVE-2024-5883, update the Ultimate Classified Listings WordPress plugin to version 1.3 or later.
Who is affected by CVE-2024-5883?
CVE-2024-5883 affects users of the Ultimate Classified Listings WordPress plugin prior to version 1.3.
What kind of attack can be executed using CVE-2024-5883?
CVE-2024-5883 can be exploited to perform a Reflected Cross-Site Scripting attack, targeting high privilege users like administrators.
Is there a workaround for CVE-2024-5883?
There is no official workaround for CVE-2024-5883; the recommended action is to update the plugin.