Unauthenticated SQL Injection Vulnerability in ListingPro by WordPress
CVE-2026-39438
9.3CRITICAL
What is CVE-2026-39438?
The ListingPro plugin for WordPress is affected by an unauthenticated SQL injection vulnerability present in versions up to 2.9.10. This security flaw allows unauthorized users to execute arbitrary SQL commands, potentially compromising the integrity of the database and sensitive data. Implementing security patches is critical to mitigate risks associated with this vulnerability, ensuring robust protection against potential exploits.
Affected Version(s)
ListingPro <= 2.9.10