HomeWordPress vulnerabilitiesDirectory Listings WordPress plugin
Directory Listings WordPress plugin vulnerabilities
Directory Listings WordPress plugin has 18 known vulnerabilities in this database. The most recent published record is dated 15 Mar 2025.
- Known vulnerabilities
- 18
- Active installs
- 1,000+
- Latest version
- 2.2.0
- Last updated
- 15 Apr 2025
- Most recent
- 15 Mar 2025
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Privilege escalation CVE-2025-1653 | High 8.8 | Up to 2.1.7 | Fixed in a later version (latest 2.2.0) | 15 Mar 2025 |
| PHP object injection CVE-2025-1657 | High 8.8 | Up to 2.1.7 | Fixed in a later version (latest 2.2.0) | 15 Mar 2025 |
| Broken access control CVE-2021-4381 | Critical 9.8 | Before 1.7 | Fixed in 1.7 | 7 Jun 2023 |
| Broken access control CVE-2021-4357 | Critical 9.1 | Up to 1.6.6 | Fixed in a later version (latest 2.2.0) | 7 Jun 2023 |
| Broken access control CVE-2021-4370 | Critical 9.8 | Up to 1.6.6 | Fixed in a later version (latest 2.2.0) | 7 Jun 2023 |
| Broken access control CVE-2021-4339 | High 7.5 | Up to 1.6.6 | Fixed in a later version (latest 2.2.0) | 7 Jun 2023 |
| SQL injection CVE-2021-4340 | Critical 9.8 | Up to 1.6.6 | Fixed in a later version (latest 2.2.0) | 7 Jun 2023 |
| Broken access control CVE-2021-4341 | Critical 9.8 | Up to 1.6.6 | Fixed in a later version (latest 2.2.0) | 7 Jun 2023 |
| Broken access control CVE-2021-4343 | Critical 9.8 | Up to 1.6.6 | Fixed in a later version (latest 2.2.0) | 7 Jun 2023 |
| Broken access control CVE-2021-4345 | Medium 6.5 | Up to 1.6.6 | Fixed in a later version (latest 2.2.0) | 7 Jun 2023 |
| Broken access control CVE-2021-4346 | Critical 9.8 | Up to 1.6.6 | Fixed in a later version (latest 2.2.0) | 7 Jun 2023 |
| Broken access control CVE-2021-36874 | High 7.1 | Up to 2.0.5 | Fixed in a later version (latest 2.2.0) | 27 Sep 2021 |
| Cross-site scripting (XSS) CVE-2021-36875 | Medium 5.9 | Up to 2.0.5 | Fixed in a later version (latest 2.2.0) | 27 Sep 2021 |
| Cross-site request forgery (CSRF) CVE-2021-36876 | Medium 5.4 | Up to 2.0.5 | Fixed in a later version (latest 2.2.0) | 27 Sep 2021 |
| Cross-site request forgery (CSRF) CVE-2021-36877 | Medium 4.3 | Up to 2.0.5 | Fixed in a later version (latest 2.2.0) | 27 Sep 2021 |
| Privilege escalation CVE-2021-36879 | Critical 9.8 | Up to 2.0.5 | Fixed in a later version (latest 2.2.0) | 27 Sep 2021 |
| SQL injection CVE-2021-36880 | High 8.6 | Up to 2.0.3 | Fixed in a later version (latest 2.2.0) | 27 Sep 2021 |
| Cross-site request forgery (CSRF) CVE-2021-36878 | Medium 4.3 | Up to 2.0.5 | Fixed in a later version (latest 2.2.0) | 27 Sep 2021 |
Read the published descriptions
- CVE-2025-1653, 15 Mar 2025
- The Directory Listings WordPress plugin - uListing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.0. This is due to the stm_listing_profile_edit AJAX action not having enough restriction on the user meta that can be updated. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator. CVE record
- CVE-2025-1657, 15 Mar 2025
- The Directory Listings WordPress plugin - uListing plugin for WordPress is vulnerable to unauthorized modification of data and PHP Object Injection due to a missing capability check on the stm_listing_ajax AJAX action in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update post meta data and inject PHP Objects that may be unserialized. A capability check was added in 2.1.8, but the unserialize is still present. CVE record
- CVE-2021-4381, 7 Jun 2023
- The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout::import_new_layout method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any WordPress option in the database. CVE record
- CVE-2021-4357, 7 Jun 2023
- The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to arbitrarily delete site posts and pages. CVE record
- CVE-2021-4370, 7 Jun 2023
- The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack security nonces, and data is seldom validated. This issue exists in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to conduct numerous administrative actions, including those less critical than the explicitly outlined ones in our detection. CVE record
- CVE-2021-4339, 7 Jun 2023
- The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file on the /1/api/ulisting-user/search REST-API route in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to retrieve the list of all users and their email address in the database. CVE record
- CVE-2021-4340, 7 Jun 2023
- The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2021-4341, 7 Jun 2023
- The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm_update_email_data AJAX action in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any WordPress option in the database. CVE record
- CVE-2021-4343, 7 Jun 2023
- The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. This is due to the stm_listing_register AJAX action function being accessible and taking roles unprotected. This makes it possible for unauthenticated attackers to create accounts, even those with administrator privileges. CVE record
- CVE-2021-4345, 7 Jun 2023
- The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on the UlistingUserRole::save_role_api method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to remove or add roles, and add capabilities. CVE record
- CVE-2021-4346, 7 Jun 2023
- The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible for unauthenticated attackers to edit any account on the blog, such as changing the admin account's email address. CVE record
- CVE-2021-36874, 27 Sep 2021
- Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5). CVE record
- CVE-2021-36875, 27 Sep 2021
- Cross-site Scripting (XSS) vulnerability in Stylemix Directory Listings WordPress plugin - uListing allows Reflected XSS.This issue affects Directory Listings WordPress plugin - uListing: from n/a through 2.0.5. CVE record
- CVE-2021-36876, 27 Sep 2021
- Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks CSRF checks on plugin administration pages. CVE record
- CVE-2021-36877, 27 Sep 2021
- Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles. CVE record
- CVE-2021-36879, 27 Sep 2021
- Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration. CVE record
- CVE-2021-36880, 27 Sep 2021
- Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom. CVE record
- CVE-2021-36878, 27 Sep 2021
- Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings. CVE record
What to do if you run Directory Listings WordPress plugin
If you run Directory Listings WordPress plugin, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Directory Listings WordPress plugin vulnerabilities
Free. We email you when a new vulnerability is published for Directory Listings WordPress plugin, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.