← back
CVE-2022-3921critical

Listingo < 3.2.7 - Unauthenticated Arbitrary File Upload

53Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.8epss 21%
exploitation probability
21%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · Listingo
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.