← WordPress Vulnerabilities
WordPress security by component

ListingPro

ListingPro is a WordPress component with 18 published CVE records in this archive. The latest tracked vulnerability was published Jun 26, 2026; the highest CVE/CNA score is 9.8.

Theme slug: listingpro

CVE-2026-56046: ListingPro: Cross-site scripting

ListingPro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.9.11.

PublishedJun 26, 2026
Known safe version2.9.12
Safe version
Jun 26, 2026 CVE-2026-56046
ListingPro: Cross-site scripting
ListingPro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.9.11.
2.9.12
CVE6.5
NVDPending
Dec 18, 2025 CVE-2025-64378
ListingPro: A security weakness
ListingPro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.1
NVDPending
Dec 18, 2025 CVE-2025-64377
ListingPro: Filesystem traversal
ListingPro is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.1
NVDPending
Dec 18, 2025 CVE-2025-64376
ListingPro: Cross-site scripting
ListingPro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Dec 18, 2025 CVE-2025-63039
ListingPro: A security weakness
ListingPro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Dec 09, 2025 CVE-2025-63047
ListingPro: A security weakness
ListingPro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jan 02, 2025 CVE-2024-39623
ListingPro: Privilege escalation or authentication bypass
ListingPro is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVD8.8
Aug 29, 2024 CVE-2024-39622
ListingPro: SQL injection
ListingPro is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.3
NVD9.8
Aug 29, 2024 CVE-2024-39620
ListingPro: SQL injection
ListingPro is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVD8.8
Aug 29, 2024 CVE-2024-38795
ListingPro: SQL injection
ListingPro is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.3
NVD9.8
Aug 01, 2024 CVE-2024-39624
ListingPro: Filesystem traversal
ListingPro is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.5
NVD8.8
Aug 01, 2024 CVE-2024-39621
ListingPro: Filesystem traversal
ListingPro is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.0
NVD7.2
Aug 01, 2024 CVE-2024-39619
ListingPro: Filesystem traversal
ListingPro is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE9.0
NVD9.8
Jun 07, 2023 CVE-2020-36723
ListingPro - WordPress Directory & Listing: A security weakness
ListingPro - WordPress Directory & Listing is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Jun 07, 2023 CVE-2020-36719
ListingPro - WordPress Directory & Listing: A security weakness
ListingPro - WordPress Directory & Listing is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8
Dec 26, 2019 CVE-2019-19542
Listingpro: Cross-site scripting
Listingpro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Dec 26, 2019 CVE-2019-19541
Listingpro: Cross-site scripting
Listingpro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Dec 26, 2019 CVE-2019-19540
Listingpro: Cross-site scripting
Listingpro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1