Executive brief
uListing, a WordPress plugin used for creating business directories and listings, contains a security flaw that allows users with 'Contributor' level access to perform actions they should not be authorized to do. This could allow an internal user with limited permissions to modify settings or data within the plugin, potentially disrupting the directory service. While the risk is considered medium, it requires an attacker to already have a valid account on the website.
Technical details
The uListing plugin for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862) in versions up to and including 2.2.0. A remote attacker with Contributor-level privileges can exploit this vulnerability to execute functions or modify data that should be restricted to higher-privileged users. The attack is carried out over the network without requiring user interaction. As of the advisory date, no official patch has been released, and the vulnerability is classified with a CVSS 3.1 base score of 4.3.
Affected products
- StylemixThemes uListing <= 2.2.0
Timeline
- 2025-11-16: other: Reported by researcher daroo
- 2026-07-22: advisory: Advisory published by Patchstack
- 2026-07-23: disclosed: CVE published to NVD