← WordPress Vulnerabilities
WordPress security by component

Ultimate Classified Listings

Ultimate Classified Listings is a WordPress component with 9 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2025; the highest CVE/CNA score is 8.1.

Plugin slug: ultimate-classified-listings

CVE-2025-9874: Ultimate Classified Listings: Filesystem traversal

Ultimate Classified Listings is affected by filesystem traversal. Exploitation requires at least contributor-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.

PublishedSep 11, 2025
Safe version guidanceSee mitigation notes
Safe version
Sep 11, 2025 CVE-2025-9874
Ultimate Classified Listings: Filesystem traversal
Ultimate Classified Listings is affected by filesystem traversal. Exploitation requires at least contributor-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Sep 11, 2025 CVE-2025-0763
Ultimate Classified Listings: A security weakness
Ultimate Classified Listings is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Feb 20, 2025 CVE-2024-13753
Ultimate Classified Listings: Privilege escalation or authentication bypass
Ultimate Classified Listings is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.1
NVD8.8
Feb 20, 2025 CVE-2024-13748
Ultimate Classified Listings: Cross-site scripting
Ultimate Classified Listings is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Dec 02, 2024 CVE-2024-52487
Ultimate Classified Listings: Cross-site scripting
Ultimate Classified Listings is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Nov 20, 2024 CVE-2024-52448
Ultimate Classified Listings: Filesystem traversal
Ultimate Classified Listings is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Aug 01, 2024 CVE-2024-6529
Ultimate Classified Listings: Cross-site scripting
Ultimate Classified Listings is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Jul 29, 2024 CVE-2024-5883
Ultimate Classified Listings: Cross-site scripting
Ultimate Classified Listings is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.7
NVDPending
Jul 29, 2024 CVE-2024-5882
Ultimate Classified Listings: A security weakness
Ultimate Classified Listings is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending