The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 10 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Webcodingplace
Webcodingplace ultimate Classified Listings
Weaknesses CWE-22
CPEs cpe:2.3:a:webcodingplace:ultimate_classified_listings:*:*:*:*:*:wordpress:*:*
Vendors & Products Webcodingplace
Webcodingplace ultimate Classified Listings

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-01T21:25:02.969Z

Reserved: 2024-06-11T19:12:54.984Z

Link: CVE-2024-5882

cve-icon Vulnrichment

Updated: 2024-08-01T21:25:02.969Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-29T06:15:02.547

Modified: 2025-04-10T13:52:09.533

Link: CVE-2024-5882

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.