Listingpro
Vendor:
First CVE: Dec 26, 2019 · Active for 6 years
12
Total CVEs
More Total CVEs than 90% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Listingpro over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 26, 2019
6 years ago
Most Recent CVE
Jan 2, 2025
568 days ago
CVE Severity & Scoring
Listingpro12 CVEs
33%
33%
33%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (66.7%)
Unknown0 (0.0%)
Required4 (33.3%)
Privileges Required
Low4 (33.3%)
High1 (8.3%)
None7 (58.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36719CRITICAL The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1. This is due | Jun 7, 2023 | 9.8 | 39 | NO | YES |
CVE-2024-39619CRITICAL Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP Local File Inclusion.This issue | Aug 1, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-39622CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro allows SQL Injection.This issue affects Lis | Aug 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-38795CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro-plugin allows SQL Injection.This issue affe | Aug 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2020-36723MEDIUM The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6.1 via the ~/listingpro-plugin/functions.php file. | Jun 7, 2023 | 5.3 | 27 | NO | YES |
CVE-2024-39620HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro-plugin allows SQL Injection.This issue affe | Aug 29, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-39624HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro allows PHP Local File Inclusion.This issue affect | Aug 1, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-39623HIGH Cross-Site Request Forgery (CSRF) vulnerability in CridioStudio ListingPro listingpro allows Authentication Bypass.This issue affects ListingPro: from n/a through <= 2.9.4. | Jan 2, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-39621HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP Local File Inclusion.This issue | Aug 1, 2024 | 7.2 | 21 | NO | NO |
CVE-2019-19540MEDIUM The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage. | Dec 26, 2019 | 6.1 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
16.7% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Listingpro
Top CWEs
Versions
No cataloged versions.