ThreatPress

WordPress Vulnerability Database

Back

WordPress ListingPro theme <= 2.6 - Unauthenticated Arbitrary Plugin Installation/Activation/Deactivation vulnerability

Product
ListingPro
Description
Unauthenticated Arbitrary Plugin Installation/Activation/Deactivation vulnerability found by Jerome Bruandet (NinTechNet) in WordPress ListingPro theme (versions <= 2.6).
Solution
Update the WordPress ListingPro theme to the latest available version (at least 2.6.1).
Classification
Type Unknown
OWASP Top 10 A7: Missing Function Level Access Control
References
Vulnerability details
Theme changelog
CVE
Name CVE-N/A
Versions
Affected In <= 2.6
Fixed In 2.6.1
Disclosure date
2020-12-17
Credits
Jerome Bruandet (NinTechNet)