Ultimate Classified Listings
cpe:2.3:a:webcodingplace:ultimate_classified_listings:*:*:*:*:wordpress:*:*
- <= 1.6
A vulnerability exists in the Ultimate Classified Listings WordPress plugin, all versions through 1.6, allowing authenticated users with Subscriber-level access and above to unauthorizedly modify plugin custom fields. This issue arises from a lack of proper capability checks in the save_custom_fields function, enabling these users to alter data that they should not have permission to change.
Exploitation of this vulnerability could lead to unauthorized changes in plugin custom fields, potentially allowing for manipulation of listing data or other related information.
No known patch is available. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.