Arbitrary Shortcode Execution in Listingo Theme for WordPress
CVE-2024-13815
What is CVE-2024-13815?
The Listingo theme for WordPress is susceptible to a vulnerability that permits arbitrary shortcode execution. This issue arises from the failure to adequately validate input values before executing the do_shortcode function, allowing unauthenticated attackers to run malicious shortcodes. As a result, this vulnerability opens the door to various attacks, exposing users to potential risks. All versions of the Listingo theme up to and including 3.2.7 are impacted, making it crucial for users to take preventive measures and update to the latest version to safeguard their sites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Listingo * <= 3.2.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved