CVE-2024-13753

HIGH CVSS 3.1: 8.8 EPSS 0.25%
Updated Feb 25, 2025
Webcodingplace
Parameter Value
CVSS 8.8 (HIGH)
Affected Versions before 1.4
Type CWE-352 (Cross-Site Request Forgery (CSRF))
Vendor Webcodingplace
Public PoC No

The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the update_profile function. This makes it possible for unauthenticated attackers to modify victim's email via a forged request, which might lead to account takeover, granted they can trick a user into performing an action such as clicking on a link.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Webcodingplace Ultimate_Classified_Listings
cpe:2.3:a:webcodingplace:ultimate_classified_listings:*:*:*:*:*:wordpress:*:*
<= 1.4