Listingo < 3.2.7 - Unauthenticated Arbitrary File Upload
53Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.8epss 21%
exploitation probability
21%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · Listingopublic PoCs found — 1
cve_referencewpscan.com/vulnerability/e39b59b0-f24f-4de5-a21c-c4de34c3a14funverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.