Vulnerability CVE-2024-5882


Published: 2024-07-29

Description:
The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page

 References:
https://wpscan.com/vulnerability/5e8d7808-8f3e-4fc9-a1e7-e108da031ca7/

Copyright 2026, cxsecurity.com

 

Back to Top