Vulnerability Description
The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.0. This is due to the stm_listing_profile_edit AJAX action not having enough restriction on the user meta that can be updated. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Stylemixthemes | Ulisting | <= 2.1.7 |
Related Weaknesses (CWE)
References
- https://wordpress.org/plugins/ulisting/Product
- https://www.wordfence.com/threat-intel/vulnerabilities/id/4181b26e-89c7-4020-a3dMitigationThird Party Advisory
FAQ
What is CVE-2025-1653?
CVE-2025-1653 is a vulnerability with a CVSS score of 8.8 (HIGH). The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.0. This is due to the stm_listing_profile_edit A...
How severe is CVE-2025-1653?
CVE-2025-1653 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-1653?
Check the references section above for vendor advisories and patch information. Affected products include: Stylemixthemes Ulisting.