CVE-2025-1657: Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Update and PHP Object Injection
The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized modification of data and PHP Object Injection due to a missing capability check on the stmlistingajax AJAX action in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update post meta data and inject PHP Objects that may be unserialized. A capability check was added in 2.1.8, but the unserialize is still present.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1657?
CVE-2025-1657 has a high severity due to the potential for unauthorized data modification and PHP Object Injection.
How do I fix CVE-2025-1657?
To fix CVE-2025-1657, update the Directory Listings uListing plugin to version 2.1.8 or later.
What versions are affected by CVE-2025-1657?
CVE-2025-1657 affects all versions of the Directory Listings uListing plugin up to and including 2.1.7.
What type of vulnerabilities does CVE-2025-1657 introduce?
CVE-2025-1657 introduces vulnerabilities related to unauthorized modification of data and PHP Object Injection.
Who is impacted by CVE-2025-1657?
Users of the Directory Listings uListing plugin for WordPress running version 2.1.7 or earlier are impacted by CVE-2025-1657.