What the vulnerability does
01Description
The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6.1 via the ~/listingpro-plugin/functions.php file. This makes it possible for unauthenticated attackers to extract sensitive data including usernames, full names, email addresses, phone numbers, physical addresses and user post counts.
Explanation of Vulnerability in Simple Terms
02Summary
ListingPro WordPress theme versions before 2.6.1 expose sensitive information to unauthenticated attackers over the network. The vulnerability allows an attacker to read data that should be restricted, such as user details or private listing information. No user interaction or special privileges are required to exploit this flaw. Site administrators should update to version 2.6.1 or later immediately.
What an attacker can do
03Attacker Capabilities
Read sensitive information from the site without logging in, such as user data or private listings.
Potential impact on your site
04Site Impact
Visitor and user data may be exposed to anyone on the internet without your knowledge.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
June 7, 2023
CVE published
April 8, 2026
Record updated