What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through <= 2.9.4.
Explanation of Vulnerability in Simple Terms
02Summary
ListingPro versions up to 2.9.4 contain a path traversal vulnerability that allows an attacker to read, write, or delete arbitrary files on the server. The vulnerability requires specific network conditions to exploit but can affect the entire system. No authentication is required. Site administrators should update to a version newer than 2.9.4 immediately.
What an attacker can do
03Attacker Capabilities
Read, write, or delete arbitrary files on the server outside the intended directory.
Potential impact on your site
04Site Impact
Complete compromise of site files, database, and configuration; potential total site takeover or data loss.
Conditions required to exploit
05Prerequisites
Network access to the vulnerable ListingPro installation; specific network conditions required (high attack complexity).
Key dates
06Disclosure timeline
August 1, 2024
CVE published
May 11, 2026
Record updated