Sceawere
Vulnerability Detail
CVE-2026-62031UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated SQL Injection in uListing
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.3
- Creation Date
- 5h ago
- Vendor
- Stylemix
- Product
- uListing
- Attack Type
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated SQL Injection in uListing <= 2.2.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.3",
"pubDate": "2026-10-10T20:16:39.237Z",
"pubdate": "2026-10-10T20:16:39.237Z",
"executiveSummary": "The uListing plugin, in versions up to and including 2.2.0, is susceptible to an unauthenticated SQL injection vulnerability.\nThis vulnerability exists due to insufficient sanitization and validation of user-supplied input before incorporating it into database queries.\nThe flaw allows an unauthenticated remote attacker to execute arbitrary SQL commands against the underlying application database.\nSuccessful exploitation poses a critical risk to the confidentiality, integrity, and availability of the system.\nAn attacker can leverage this vulnerability to bypass authentication mechanisms, exfiltrate sensitive data, modify database records, or execute administrative operations.\nNo specific privileges or prior authentication are required to trigger this vulnerability, making it highly accessible for automated and manual exploitation attempts.\nThe exposure of this vector creates a direct path for full database compromise.",
"technicalDetails": "The vulnerability resides within the query processing logic of the uListing plugin where input parameters are passed directly to database interactions without adequate abstraction or parameterization.\nIn versions 2.2.0 and earlier, the plugin fails to utilize prepared statements or appropriate escaping functions when handling parameters destined for SQL execution.\nAn attacker can exploit this by injecting malicious SQL syntax into the vulnerable parameters, allowing the attacker to manipulate the original query structure to perform unauthorized operations.\nThe attack flow typically involves identifying a vulnerable endpoint that accepts input via GET or POST requests. The attacker crafts a payload containing SQL operators—such as UNION SELECT, SLEEP(), or conditional logic—which is then processed by the database management system.\nBecause the application does not validate the integrity of these inputs, the injected SQL is executed with the privileges of the database user configured for the application.\nThis enables Blind SQL Injection or Error-Based SQL Injection techniques, where an attacker can systematically extract database contents, including table structures, administrator credentials, and user information, by observing the server's response time or error messages.\nBeyond data exfiltration, an attacker can manipulate application logic to elevate privileges, such as creating new administrative accounts or modifying existing user records, thereby gaining unauthorized control over the WordPress installation.\nThe vulnerability is reachable over the network and requires no interaction from an authenticated user, meaning the attack surface is exposed to any remote user capable of reaching the plugin's entry points.\nThe primary root cause is a failure in the software development lifecycle to enforce the use of the WordPress Database API (e.g., $wpdb->prepare) consistently across all plugin modules handling user-supplied data."
}