WordPress security by component
ListingPro
Theme description
ListingPro is a WordPress component with 18 published CVE records in this archive. The latest tracked vulnerability was published Jun 26, 2026; the highest CVE/CNA score is 9.8.
Theme slug:
listingproLatest vulnerability
CVE-2026-56046: ListingPro: Cross-site scripting
ListingPro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.9.11.
| Safe version |
|
||
|---|---|---|---|
| Jun 26, 2026 |
CVE-2026-56046
ListingPro: Cross-site scripting
ListingPro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.9.11.
|
2.9.12 |
CVE6.5
NVDPending
|
| Dec 18, 2025 |
CVE-2025-64378
ListingPro: A security weakness
ListingPro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Dec 18, 2025 |
CVE-2025-64377
ListingPro: Filesystem traversal
ListingPro is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Dec 18, 2025 |
CVE-2025-64376
ListingPro: Cross-site scripting
ListingPro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Dec 18, 2025 |
CVE-2025-63039
ListingPro: A security weakness
ListingPro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 09, 2025 |
CVE-2025-63047
ListingPro: A security weakness
ListingPro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 02, 2025 |
CVE-2024-39623
ListingPro: Privilege escalation or authentication bypass
ListingPro is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Aug 29, 2024 |
CVE-2024-39622
ListingPro: SQL injection
ListingPro is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.3
NVD9.8
|
| Aug 29, 2024 |
CVE-2024-39620
ListingPro: SQL injection
ListingPro is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVD8.8
|
| Aug 29, 2024 |
CVE-2024-38795
ListingPro: SQL injection
ListingPro is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.3
NVD9.8
|
| Aug 01, 2024 |
CVE-2024-39624
ListingPro: Filesystem traversal
ListingPro is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE8.5
NVD8.8
|
| Aug 01, 2024 |
CVE-2024-39621
ListingPro: Filesystem traversal
ListingPro is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE8.0
NVD7.2
|
| Aug 01, 2024 |
CVE-2024-39619
ListingPro: Filesystem traversal
ListingPro is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE9.0
NVD9.8
|
| Jun 07, 2023 |
CVE-2020-36723
ListingPro - WordPress Directory & Listing: A security weakness
ListingPro - WordPress Directory & Listing is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Jun 07, 2023 |
CVE-2020-36719
ListingPro - WordPress Directory & Listing: A security weakness
ListingPro - WordPress Directory & Listing is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Dec 26, 2019 |
CVE-2019-19542
Listingpro: Cross-site scripting
Listingpro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Dec 26, 2019 |
CVE-2019-19541
Listingpro: Cross-site scripting
Listingpro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Dec 26, 2019 |
CVE-2019-19540
Listingpro: Cross-site scripting
Listingpro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|