CVE-2020-36719
The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1. This is due to a missing capability check on the lp_cc_addons_actions function. This makes it possible for unauthenticated attackers to arbitrarily install, activate and deactivate any plugin.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.30% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- cridio/listingpro
- Source
- security@wordfence.com
References
- https://blog.nintechnet.com/wordpress-listingpro-theme-fixed-a-critical-vulnerability/Exploit
- https://themeforest.net/item/listingpro-multipurpose-directory-theme/19386460Product
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a08fa649-3092-4c26-a009-2dd576b9b1ac?source=cveThird Party Advisory
- https://blog.nintechnet.com/wordpress-listingpro-theme-fixed-a-critical-vulnerability/Exploit
- https://themeforest.net/item/listingpro-multipurpose-directory-theme/19386460Product
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a08fa649-3092-4c26-a009-2dd576b9b1ac?source=cveThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.