Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Directory Listings WordPress plugin – uListing Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 28 vulnerability records associated with Directory Listings WordPress plugin – uListing, published between 2021 and 2026.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

At a glance

Security Snapshot

28Total records
9Critical
7High
11Medium
0Low
1Informational
20Patched records
8Currently marked unpatched
2021-01-28First disclosure
2026-07-22Latest disclosure
27 of 28CVE coverage

Use this history

Check and watch Directory Listings WordPress plugin – uListing.

A history record does not establish whether the version installed on your website is affected. Enter the exact version in the checker, or add this software to a private Critical/High alert watchlist.

Year-by-Year Timeline

YearRecordsRelative volume
20211717 records
202411 records
202577 records
202633 records

Severity Breakdown

SeverityRecordsShare
Critical932.1%
High725%
Medium1139.3%
Informational13.6%

Vulnerability-Type Breakdown

Missing Authorization

12 records42.9%

First: 2021. Latest: 2026.

SQL Injection

5 records17.9%

First: 2021. Latest: 2025.

CSRF

4 records14.3%

First: 2021. Latest: 2021.

Privilege Escalation

2 records7.1%

First: 2021. Latest: 2025.

Other

2 records7.1%

First: 2025. Latest: 2025.

Cross-Site Scripting

1 record3.6%

First: 2021. Latest: 2021.

Information Disclosure

1 record3.6%

First: 2024. Latest: 2024.

Path Traversal

1 record3.6%

First: 2026. Latest: 2026.

Patch Status

Patched
20
Currently marked unpatched
8
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 2.1.7
  • 2.1.6
  • 2.0.9
  • 2.0.6
  • 2.0.4
  • 1.7

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-2.2.0Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing AuthorizationJuly 22, 2026Not suppliedMedium
*-2.2.0Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing AuthorizationJuly 22, 2026Not suppliedMedium
*-2.2.0Directory Listings WordPress plugin – uListing <= 2.2.0 - Authenticated (Editor+) Arbitrary File DownloadFebruary 26, 2026Not suppliedMedium
*-2.2.0uListing <= 2.2.0 - Authenticated (Administrator+) PHP Object InjectionApril 22, 2025Not suppliedMedium
*-2.2.0uListing <= 2.2.0 - Authenticated (Subscriber+) PHP Object InjectionApril 15, 2025Not suppliedHigh
*-2.1.9uListing <= 2.1.9 - Authenticated (Administrator+) SQL InjectionApril 4, 2025Not suppliedMedium
*-2.2.0Directory Listings WordPress plugin – uListing <= 2.2.0 - Authenticated (Subscriber+) Privilege EscalationMarch 14, 2025Not suppliedHigh
*-2.2.0Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Update and PHP Object InjectionMarch 14, 2025Not suppliedHigh
*-2.1.6uListing <= 2.1.6 - Authenticated (Contributor+) SQL InjectionFebruary 3, 20252.1.7Medium
*-2.1.6uListing <= 2.1.6 - Unauthenticated SQL InjectionFebruary 3, 20252.1.7High
*-2.1.5uListing <= 2.1.5 - Unauthenticated Information ExposureSeptember 27, 20242.1.6Medium
[*, 1.7)uListing <= 1.6.6 - Unauthenticated SQL InjectionOctober 28, 20211.7Critical
*-2.0.8Listing, Classified Ads & Business Directory – uListing <= 2.0.8 - Cross-Site Request ForgerySeptember 6, 20212.0.9High
*-2.0.5Listing, Classified Ads & Business Directory – uListing <= 2.0.5 - Privilege EscalationJuly 27, 20212.0.6Critical
*-2.0.5uListing <= 2.0.5 - Cross-Site Request Forgery leading to Settings ChangeJuly 27, 20212.0.6Medium
*-2.0.5Listing, Classified Ads & Business Directory – uListing <= 2.0.5 - Cross-Site Request ForgeryJuly 27, 20212.0.6Medium
*-2.0.5Listing, Classified Ads & Business Directory – uListing <= 2.0.5 - Cross-Site Request ForgeryJuly 27, 20212.0.6Medium
*-2.0.5Listing, Classified Ads & Business Directory – uListing <= 2.0.5 - Reflected Cross-Site ScriptingJuly 27, 20212.0.6Medium
*-2.0.5uListing plugin <= 2.0.5 - Authenticated Insecure Direct Object References (IDOR)July 27, 20212.0.6High
*-2.0.3Listing, Classified Ads & Business Directory – uListing <= 2.0.3 - Unauthenticated SQL InjectionJuly 26, 20212.0.4Critical
[*, 1.7)uListing <= 1.6.6 - Unauthenticated Options Changes via wp_routeJanuary 28, 20211.7Critical
[*, 1.7)uListing <= 1.6.6 - Missing AuthorizationJanuary 28, 20211.7Critical
[*, 1.7)uListing <= 1.6.6 - Unauthenticated Arbitrary Post/Page DeletionJanuary 28, 20211.7Critical
[*, 1.7)uListing <= 1.6.6 - Unauthenticated Arbitrary Roles and Capabilities Creation/DeletionJanuary 28, 20211.7Medium
[*, 1.7)uListing <= 1.6.6 - Unauthenticated Arbitrary Account ChangesJanuary 28, 20211.7Critical

Selected source records

Latest Records

MediumCVE-2026-27392

Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization

Published: July 22, 2026

Affected versions
*-2.2.0
Patched versions
Not supplied
Original Wordfence record
MediumCVE-2026-27391

Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization

Published: July 22, 2026

Affected versions
*-2.2.0
Patched versions
Not supplied
Original Wordfence record
MediumCVE-2026-28078

Directory Listings WordPress plugin – uListing <= 2.2.0 - Authenticated (Editor+) Arbitrary File Download

Published: February 26, 2026

Affected versions
*-2.2.0
Patched versions
Not supplied
Original Wordfence record
MediumCVE-2026-28138

uListing <= 2.2.0 - Authenticated (Administrator+) PHP Object Injection

Published: April 22, 2025

Affected versions
*-2.2.0
Patched versions
Not supplied
Original Wordfence record
HighCVE-2025-32662

uListing <= 2.2.0 - Authenticated (Subscriber+) PHP Object Injection

Published: April 15, 2025

Affected versions
*-2.2.0
Patched versions
Not supplied
Original Wordfence record
MediumCVE-2025-32122

uListing <= 2.1.9 - Authenticated (Administrator+) SQL Injection

Published: April 4, 2025

Affected versions
*-2.1.9
Patched versions
Not supplied
Original Wordfence record
HighCVE-2025-1653

Directory Listings WordPress plugin – uListing <= 2.2.0 - Authenticated (Subscriber+) Privilege Escalation

Published: March 14, 2025

Affected versions
*-2.2.0
Patched versions
Not supplied
Original Wordfence record
HighCVE-2025-1657

Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Update and PHP Object Injection

Published: March 14, 2025

Affected versions
*-2.2.0
Patched versions
Not supplied
Original Wordfence record

Highest-Severity Records

CriticalCVE-2021-4340

uListing <= 1.6.6 - Unauthenticated SQL Injection

Published: October 28, 2021

Affected versions
[*, 1.7)
Patched versions
1.7
Original Wordfence record
CriticalCVE-2021-4341

uListing <= 1.6.6 - Unauthenticated Wordpress Options Changes via AJAX

Published: January 28, 2021

Affected versions
[*, 1.7)
Patched versions
1.7
Original Wordfence record
CriticalCVE-2021-4343

uListing <= 1.6.6 - Unauthenticated Arbitrary Account Creation

Published: January 28, 2021

Affected versions
[*, 1.7)
Patched versions
1.7
Original Wordfence record
CriticalCVE-2021-4346

uListing <= 1.6.6 - Unauthenticated Arbitrary Account Changes

Published: January 28, 2021

Affected versions
[*, 1.7)
Patched versions
1.7
Original Wordfence record
CriticalCVE-2021-36879

Listing, Classified Ads & Business Directory – uListing <= 2.0.5 - Privilege Escalation

Published: July 27, 2021

Affected versions
*-2.0.5
Patched versions
2.0.6
Original Wordfence record
CriticalCVE-2021-36880

Listing, Classified Ads & Business Directory – uListing <= 2.0.3 - Unauthenticated SQL Injection

Published: July 26, 2021

Affected versions
*-2.0.3
Patched versions
2.0.4
Original Wordfence record
CriticalCVE-2021-4370

uListing <= 1.6.6 - Missing Authorization

Published: January 28, 2021

Affected versions
[*, 1.7)
Patched versions
1.7
Original Wordfence record
CriticalCVE-2021-4381

uListing <= 1.6.6 - Unauthenticated Options Changes via wp_route

Published: January 28, 2021

Affected versions
[*, 1.7)
Patched versions
1.7
Original Wordfence record

Currently Marked Unpatched Records

MediumCVE-2026-27392

Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization

Published: July 22, 2026

Affected versions
*-2.2.0
Patched versions
Not supplied
Original Wordfence record
MediumCVE-2026-27391

Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization

Published: July 22, 2026

Affected versions
*-2.2.0
Patched versions
Not supplied
Original Wordfence record
MediumCVE-2026-28078

Directory Listings WordPress plugin – uListing <= 2.2.0 - Authenticated (Editor+) Arbitrary File Download

Published: February 26, 2026

Affected versions
*-2.2.0
Patched versions
Not supplied
Original Wordfence record
MediumCVE-2026-28138

uListing <= 2.2.0 - Authenticated (Administrator+) PHP Object Injection

Published: April 22, 2025

Affected versions
*-2.2.0
Patched versions
Not supplied
Original Wordfence record
HighCVE-2025-32662

uListing <= 2.2.0 - Authenticated (Subscriber+) PHP Object Injection

Published: April 15, 2025

Affected versions
*-2.2.0
Patched versions
Not supplied
Original Wordfence record
MediumCVE-2025-32122

uListing <= 2.1.9 - Authenticated (Administrator+) SQL Injection

Published: April 4, 2025

Affected versions
*-2.1.9
Patched versions
Not supplied
Original Wordfence record
HighCVE-2025-1653

Directory Listings WordPress plugin – uListing <= 2.2.0 - Authenticated (Subscriber+) Privilege Escalation

Published: March 14, 2025

Affected versions
*-2.2.0
Patched versions
Not supplied
Original Wordfence record
HighCVE-2025-1657

Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Update and PHP Object Injection

Published: March 14, 2025

Affected versions
*-2.2.0
Patched versions
Not supplied
Original Wordfence record

View all associated vulnerabilities

3Zero Interpretation

uListing stands out in this pilot because the synchronized source currently marks a meaningful portion of its history as unpatched. The dataset contains 28 records from January 2021 through July 2026, including nine critical and seven high-severity records. Missing authorization is the dominant category with 12 records (42.9%), followed by five SQL-injection and four CSRF records.

Eight of the 28 records are currently marked unpatched. Recent entries affecting versions through 2.2.0 include missing authorization, arbitrary file download and PHP object injection; the history also contains privilege-escalation and SQL-injection records. This does not establish that every uListing installation is exploitable, but it does make exact version matching and feature exposure more urgent than a routine update-only response.

The patch state reflects the synchronized Wordfence source and may change when the vendor or source record is updated. It should be verified again before making a production decision.

Practical Next Steps

  1. Identify whether uListing is installed, active and business-critical. Record the exact version and which front-end listing, account, upload and submission features are enabled.
  2. Check every matching affected range. The synchronized dataset currently marks recent records through 2.2.0 as unpatched. Do not assume older patched values such as 2.1.7 resolve records that were published later.
  3. Review the vendor’s current release and advisory status. If no confirmed fix covers the matching records, consider disabling and removing the plugin after preserving listing data and planning a replacement.
  4. Reduce exposure while a decision is pending. Restrict registration and listing submission, remove unnecessary privileged accounts, protect administrative access and monitor file-download and account activity.
  5. Investigate if exposure coincided with warning signs. Unknown users, altered listings, unexpected file downloads, injected objects or database changes require a manual review. An unpatched source record alone is not proof of compromise.

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory