Arbitrary Shortcode Execution in Listingo Theme for WordPress
CVE-2024-13815
6.5MEDIUM
What is CVE-2024-13815?
The Listingo theme for WordPress is susceptible to a vulnerability that permits arbitrary shortcode execution. This issue arises from the failure to adequately validate input values before executing the do_shortcode function, allowing unauthenticated attackers to run malicious shortcodes. As a result, this vulnerability opens the door to various attacks, exposing users to potential risks. All versions of the Listingo theme up to and including 3.2.7 are impacted, making it crucial for users to take preventive measures and update to the latest version to safeguard their sites.
Affected Version(s)
Listingo * <= 3.2.7