Unauthenticated SQL Injection Vulnerability in ListingPro by WordPress
CVE-2026-39438

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 June 2026

What is CVE-2026-39438?

The ListingPro plugin for WordPress is affected by an unauthenticated SQL injection vulnerability present in versions up to 2.9.10. This security flaw allows unauthorized users to execute arbitrary SQL commands, potentially compromising the integrity of the database and sensitive data. Implementing security patches is critical to mitigate risks associated with this vulnerability, ensuring robust protection against potential exploits.

Affected Version(s)

ListingPro <= 2.9.10

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO | Patchstack Bug Bounty Program
.