Path Traversal Vulnerability in CridioStudio ListingPro Plugin
CVE-2024-39621

8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 August 2024

What is CVE-2024-39621?

The ListingPro plugin from CridioStudio contains a vulnerability that allows local file inclusion through improper limitation of pathname access. This flaw can lead to unauthorized file access on the server, potentially exposing sensitive information or enabling further attacks. The affected versions range from n/a to 2.9.3, emphasizing the importance of timely updates and security patches.

Affected Version(s)

ListingPro 0 <= 2.9.4

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.