Junglewise Threat Intelligence

CVE-2026-56046: CridioStudio ListingPro cross-site scripting in WordPress theme

CVE-2026-56046 · Severity: medium · CVSS 6.5 · Published 2026-06-26

Technologies: CridioStudio ListingPro.

Executive brief

ListingPro, a popular WordPress theme used for creating directory and listing websites, contains a security flaw that allows users with basic 'Subscriber' accounts to inject malicious scripts. If an administrator or another user views the affected area, these scripts could execute, potentially leading to unauthorized actions, data theft, or website redirection. Business owners should update the theme immediately to prevent attackers from compromising their site's integrity or redirecting visitors to malicious content.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the CridioStudio ListingPro theme for WordPress through version 2.9.11. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with Subscriber-level privileges can inject malicious JavaScript into the application. The exploit requires a victim (such as an administrator) to interact with the affected page or perform a specific action for the script to execute. Successful exploitation allows for session hijacking, unauthorized administrative actions, or defacement. The issue is resolved in version 2.9.12.

Affected products

  • CridioStudio ListingPro <= 2.9.11

Timeline

  • 2026-04-21: disclosed: Reported by security researcher daroo
  • 2026-06-24: advisory: Patchstack published advisory details
  • 2026-06-26: patched: Version 2.9.12 released to address the vulnerability

References