The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 05 Mar 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. | |
Title | Listingo - Business Listing and Directory WordPress Theme <= 3.2.7 - Unauthenticated Arbitrary Shortcode Execution | |
Weaknesses | CWE-94 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-03-05T09:21:49.762Z
Updated: 2025-03-05T14:15:27.825Z
Reserved: 2025-01-30T21:15:14.506Z
Link: CVE-2024-13815

Updated: 2025-03-05T14:15:24.113Z

Status : Received
Published: 2025-03-05T10:15:18.210
Modified: 2025-03-05T10:15:18.210
Link: CVE-2024-13815

No data.