Description
The Ultimate Classified Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_custom_fields function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change plugin custom fields.
Problem types
Product status
* (semver)
Timeline
| 2025-01-27: | Discovered |
| 2025-09-10: | Disclosed |
Credits
Ivan Kuzymchak
References
www.wordfence.com/...-e436-412a-9a88-89d128d72aa0?source=cve
plugins.trac.wordpress.org/...asses/class-admin-settings.php