CVE-2020-36719: ListingPro - WordPress Directory & Listing Theme < 2.6.1 - Arbitrary Plugin Installation, Activation and Deactivation
The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1. This is due to a missing capability check on the lpccaddonsactions function. This makes it possible for unauthenticated attackers to arbitrarily install, activate and deactivate any plugin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36719?
CVE-2020-36719 is considered a critical vulnerability due to its potential for arbitrary plugin installation and control of the WordPress site.
How do I fix CVE-2020-36719?
To fix CVE-2020-36719, update your ListingPro theme to version 2.6.1 or later.
What causes CVE-2020-36719?
CVE-2020-36719 is caused by a missing capability check in the lp_cc_addons_actions function.
Who is affected by CVE-2020-36719?
Users of the ListingPro theme for WordPress prior to version 2.6.1 are affected by CVE-2020-36719.
Can unauthenticated attackers exploit CVE-2020-36719?
Yes, unauthenticated attackers can exploit CVE-2020-36719 to install and activate plugins without authorization.