Vulnerabilities > CVE-2020-36723 - Unspecified vulnerability in Cridio Listingpro
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6.1 via the ~/listingpro-plugin/functions.php file. This makes it possible for unauthenticated attackers to extract sensitive data including usernames, full names, email addresses, phone numbers, physical addresses and user post counts.
Vulnerable Configurations
References
- https://blog.nintechnet.com/wordpress-listingpro-theme-fixed-a-critical-vulnerability/
- https://blog.nintechnet.com/wordpress-listingpro-theme-fixed-a-critical-vulnerability/
- https://themeforest.net/item/listingpro-multipurpose-directory-theme/19386460
- https://themeforest.net/item/listingpro-multipurpose-directory-theme/19386460
- https://www.wordfence.com/threat-intel/vulnerabilities/id/b9b21f8e-8d66-4d3e-a383-bea20a3c4498?source=cve
- https://www.wordfence.com/threat-intel/vulnerabilities/id/b9b21f8e-8d66-4d3e-a383-bea20a3c4498?source=cve