ZeroHour

Vulnerabilities

12 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-39623
Cross-Site Request Forgery (CSRF) vulnerability in CridioStudio ListingPro listingpro allows Authentication Bypass.This issue affects ListingPro:

Cross-Site Request Forgery (CSRF) vulnerability in CridioStudio ListingPro listingpro allows Authentication Bypass.This issue affects ListingPro: from n/a through <= 2.9.4.

NVD description · AI analysis pending
8.8<1%
  • cridio listingpro
CVE-2024-39622
+2 in the same advisory: …38795 …39620
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro allows SQL Injection.Th

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro allows SQL Injection.This issue affects ListingPro: from n/a through <= 2.9.4.

NVD description · AI analysis pending
9.8
group max
<1%
  • cridio listingpro
CVE-2024-39619
+2 in the same advisory: …39624 …39621
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP Local File

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through <= 2.9.4.

NVD description · AI analysis pending
9.8
group max
<1%
  • cridio listingpro
CVE-2020-36719
+1 in the same advisory: …36723
The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions befor

The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1. This is due to a missing capability check on the lp_cc_addons_actions function. This makes it possible for unauthenticated attackers to arbitrarily install, activate and deactivate any plugin.

NVD description · AI analysis pending
9.8
group max
4% PoC
  • cridio listingpro
CVE-2019-19540
+2 in the same advisory: …19541 …19542
The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage.

The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • cridio listingpro