Executive brief
ListingPro, a popular WordPress plugin used for creating directory and listing websites, contains a security flaw that allows users with basic 'Subscriber' accounts to perform actions they should not be authorized to access. This could allow low-level users to view restricted information or modify certain site settings, potentially compromising the integrity of the directory data. While the impact is considered moderate, it represents a failure in the system's permission controls.
Technical details
A broken access control vulnerability exists in the ListingPro plugin for WordPress (versions <= 2.9.10) due to missing authorization checks (CWE-862). The flaw allows an authenticated attacker with low-level 'Subscriber' privileges to execute functions or access data that should be restricted to higher-privileged roles. The attack is reachable over the network and does not require user interaction. As of the advisory date, no official patch has been released, and the vulnerability remains unpatched in version 2.9.10.
Affected products
- CridioStudio ListingPro <= 2.9.10
Timeline
- 2026-01-22: disclosed: Reported by Phat RiO to Patchstack
- 2026-07-22: advisory: Patchstack published advisory
- 2026-07-23: advisory: NVD published CVE record