Themographics Listingo vulnerabilities
2 known vulnerabilities affecting themographics/listingo.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2022-3921P2CRITICALCVSS 9.8fixed in 3.2.72022-12-12
CVE-2022-3921 [CRITICAL] CWE-434 CVE-2022-3921: The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action
The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE
nvd
CVE-2024-13815P3MEDIUMCVSS 6.5≤ 3.2.72025-03-05
CVE-2024-13815 [MEDIUM] CWE-94 CVE-2024-13815: The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions
The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
nvd