9.8
CVSSv3

CVE-2020-36719

Published: 07/06/2023 Updated: 07/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions prior to 2.6.1. This is due to a missing capability check on the lp_cc_addons_actions function. This makes it possible for unauthenticated malicious users to arbitrarily install, activate and deactivate any plugin.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cridio listingpro