Ultimate Classified Listings
Vendor:
First CVE: Jul 29, 2024 · Active for 1 year
9
Total CVEs
More Total CVEs than 88% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 35% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ultimate Classified Listings over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 29, 2024
23 months ago
Most Recent CVE
Sep 11, 2025
320 days ago
CVE Severity & Scoring
Ultimate Classified Listings9 CVEs
44%
56%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (77.8%)
High2 (22.2%)
Unknown0 (0.0%)
User Interaction
None4 (44.4%)
Unknown0 (0.0%)
Required5 (55.6%)
Privileges Required
Low4 (44.4%)
High1 (11.1%)
None4 (44.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9874HIGH The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6 via the 'uclwp_dashboard' shortcode. This make | Sep 11, 2025 | 7.5 | 26 | NO | NO |
CVE-2024-13753HIGH The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect non | Feb 20, 2025 | 8.8 | 25 | NO | NO |
CVE-2024-5882HIGH The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the serv | Jul 29, 2024 | 7.5 | 23 | NO | NO |
CVE-2024-6529HIGH The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scrip | Aug 1, 2024 | 7.1 | 21 | NO | NO |
CVE-2024-52448HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Ultimate Classified Listings ultimate-classified-listings allows PHP | Nov 20, 2024 | 7.5 | 20 | NO | NO |
CVE-2025-0763MEDIUM The Ultimate Classified Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_custom_fields function in all | Sep 11, 2025 | 4.3 | 18 | NO | NO |
CVE-2024-52487MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webcodingplace Ultimate Classified Listings ultimate-classified-listings allow | Dec 2, 2024 | 6.5 | 18 | NO | NO |
CVE-2024-13748MEDIUM The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title parameter in all versions up to, and including, 1.4 due to insuffic | Feb 20, 2025 | 4.8 | 16 | NO | NO |
CVE-2024-5883MEDIUM The Ultimate Classified Listings WordPress plugin before 1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scrip | Jul 29, 2024 | 4.7 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Ultimate Classified Listings
Top CWEs
Versions
No cataloged versions.