Cridio / Listingpro
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-39623 | WordPress ListingPro theme <= 2.9.4 - Cross Site Request Forgery (CSRF) to Account Takeover vulnerability | HIGH | 8.8 | Jan 2, 2025 |
| CVE-2024-39622 | WordPress ListingPro theme <= 2.9.4 - Unauthenticated SQL Injection vulnerability | CRITICAL | 9.8 | Aug 29, 2024 |
| CVE-2024-39620 | WordPress ListingPro plugin <= 2.9.4 - SQL Injection vulnerability | HIGH | 8.8 | Aug 29, 2024 |
| CVE-2024-38795 | WordPress ListingPro plugin <= 2.9.4 - Unauthenticated SQL Injection vulnerability | CRITICAL | 9.8 | Aug 29, 2024 |
| CVE-2024-39619 | WordPress ListingPro plugin <= 2.9.4 - Unauthenticated Local File Inclusion vulnerability | CRITICAL | 9.8 | Aug 1, 2024 |
| CVE-2024-39621 | WordPress ListingPro plugin <= 2.9.4 - Local File Inclusion vulnerability | HIGH | 8.0 | Aug 1, 2024 |
| CVE-2024-39624 | WordPress ListingPro theme <= 2.9.4 - Local File Inclusion vulnerability | HIGH | 8.8 | Aug 1, 2024 |
| CVE-2020-36723 | ListingPro - WordPress Directory & Listing Theme < 2.6.1 - Sensitive Information Disclosure | MEDIUM | 5.3 | Jun 7, 2023 |
| CVE-2020-36719 | ListingPro - WordPress Directory & Listing Theme < 2.6.1 - Arbitrary Plugin Installation, Activation and Deactivation | CRITICAL | 9.8 | Jun 7, 2023 |
| CVE-2019-19540 | The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage. | MEDIUM | 6.1 | Dec 26, 2019 |
| CVE-2019-19541 | The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Best Day/Night field on the new listing submit page. | MEDIUM | 5.4 | Dec 26, 2019 |
| CVE-2019-19542 | The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit page. | MEDIUM | 5.4 | Dec 26, 2019 |
Showing 1 to 12 of 12 CVEs