Junglewise Threat Intelligence

CVE-2026-39438: Emraan Cheema ListingPro SQL injection

CVE-2026-39438 · Severity: critical · CVSS 9.3 · Published 2026-06-17

Technologies: Emraan Cheema ListingPro. Vendors: ListingProWP.

Executive brief

ListingPro is a popular WordPress plugin used to create business directories and listing websites. A critical security flaw allows unauthorized individuals to interact directly with the website's database without needing a password. This could lead to the theft of sensitive customer information, unauthorized access to site data, or disruption of the website's operations.

Technical details

The ListingPro plugin for WordPress is vulnerable to an unauthenticated SQL injection due to improper neutralization of special elements used in an SQL command (CWE-89). The vulnerability exists in versions up to and including 2.9.10. Because the flaw is reachable by unauthenticated users over the network, an attacker can send crafted requests to the application to execute arbitrary SQL queries. This can result in the extraction of sensitive data from the database or partial impact on service availability. The issue is resolved in version 2.9.11.

Affected products

  • Emraan Cheema ListingPro <= 2.9.10

Timeline

  • 2026-02-14: other: Vulnerability reported by Phat RiO
  • 2026-04-21: advisory: Patchstack published advisory
  • 2026-06-17: disclosed: CVE published to NVD

References