External risk intelligence

Unauthenticated SQL Injection in uListing Plugin Versions <= 2.2.0

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-62031

uListing is a WordPress plugin designed to create directory and listing websites. Such plugins are inherently intended to be public-facing web components, making the vulnerable endpoints accessible to users over the internet as part of normal operation.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in the uListing plugin, potentially impacting systems that use this technology for creating directory and listing websites. This issue could allow unauthorized access to data due to a SQL injection flaw, which is a significant concern given the nature of such plugins. The primary concern is to confirm if your environment utilizes this specific plugin and if it is exposed to potential threats.

  • Unauthenticated attackers can inject malicious SQL commands.
  • Directory sites could be at risk of data compromise.
  • Confirm if uListing is used and exposed to external threats.

Attack Path

How an attacker could exploit the issue

An attacker can target any system running the vulnerable uListing plugin, as no authentication is required to access the affected component. By sending specially crafted input to the plugin, an attacker could trigger an SQL injection vulnerability. This could potentially lead to unauthorized access and modification of database information, and in some cases, denial of service.

  • No authentication needed.
  • Malicious input triggers SQL injection.
  • Database compromise and denial of service risk.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated SQL injection in uListing could allow an attacker to access or manipulate sensitive database information. This could occur when the application improperly handles user-supplied input in database queries, potentially leading to unauthorized data disclosure or service disruption.

  • Database information
  • Unsanitized input
  • Unauthorized data access

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-World Ownership:

Addressing this SQL injection vulnerability in uListing requires coordination between the application owner responsible for the WordPress site, the infrastructure or platform team managing the web hosting environment, and potentially the vendor-management team if the plugin was procured through a third party. The first practical step is to identify all instances of uListing, determine their exposure and criticality, identify the accountable owner for each instance, and then prioritize remediation efforts based on risk.

  • Application owners should lead remediation.
  • Verify public-facing, critical instances first.
  • Coordinate vendor and platform support.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the uListing plugin?

uListing is a WordPress plugin used to build directory and listing-based websites. It functions by allowing site administrators to manage, organize, and display structured data, such as real estate or business listings, directly on their site's front end for public viewing.

What does CVE-2026-62031 mean for my database?

This vulnerability is an SQL injection, classified as CWE-89. It happens when software incorrectly handles user input, allowing an attacker to insert malicious database commands. In this context, it could lead to unauthorized access to your stored information or potential service disruption.

How is this SQL injection triggered?

An attacker triggers this flaw by sending specially crafted input to the plugin. Critically, this does not require a user to log in or hold special privileges; the system processes the malicious input automatically. Input that follows standard, expected formatting for the plugin does not trigger the bug.

Why does Halo Surface Signal categorize this as external?

Because uListing is designed to power directory and listing websites, its core features are inherently public-facing. Halo Surface Signal identifies this as an external risk because the vulnerable components are typically accessible over the internet to perform their expected function.

What should I do if I use uListing?

Your first step is to inventory all WordPress sites in your environment to identify which ones have this plugin installed and active. Once identified, prioritize reviewing instances that are exposed to the internet, as these carry the highest risk, and coordinate with your site administrators to address the issue.

References