uListing <= 2.1.5 - Unauthenticated Information Exposure
2024-09-27 00:00
Joshua ChanStrategic Overview
StatusPatched in 2.1.6
Affected PluginDirectory Listings WordPress plugin – uListing
Affected Version
<= 2.1.5CVSS5.3Medium
CVE
CVE-2024-47344Vulnerability Overview
The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.5 via the /pricing-plan/payment endpoint. This makes it possible for unauthenticated attackers to render the pricing plan payment page.
Technical Analysis
REMEDIATION: Update to version 2.1.6, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C