Back
WordPress ListingPro theme <= 2.6 - Unauthenticated Arbitrary Plugin Installation/Activation/Deactivation vulnerability
- Product
- ListingPro
- Description
- Unauthenticated Arbitrary Plugin Installation/Activation/Deactivation vulnerability found by Jerome Bruandet (NinTechNet) in WordPress ListingPro theme (versions <= 2.6).
- Solution
- Update the WordPress ListingPro theme to the latest available version (at least 2.6.1).
- Classification
-
Type Unknown
OWASP Top 10 A7: Missing Function Level Access Control
- References
-
Vulnerability details
Theme changelog
- CVE
- Name CVE-N/A
- Versions
-
Affected In
<= 2.6
Fixed In 2.6.1
- Disclosure date
- 2020-12-17
- Credits
- Jerome Bruandet (NinTechNet)