CVE-2024-5882: Webcodingplace Ultimate Classified Listings
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page
Affected products
- Webcodingplace Ultimate Classified Listings: before 1.3 (fixed in 1.3)
Published 2024-07-29. Last modified 2026-06-17.