CVE-2024-39621: WordPress ListingPro plugin <= 2.9.4 - Local File Inclusion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through <= 2.9.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39621?
CVE-2024-39621 is considered a high severity vulnerability due to its potential for local file inclusion exploits.
How do I fix CVE-2024-39621?
To fix CVE-2024-39621, update ListingPro to version 2.9.4 or later where the vulnerability has been addressed.
What impact does CVE-2024-39621 have on affected systems?
CVE-2024-39621 can allow an attacker to include arbitrary files on the server, potentially leading to data breaches or system compromise.
Which versions of ListingPro are affected by CVE-2024-39621?
CVE-2024-39621 affects all versions of ListingPro up to and including version 2.9.3.
Is there a known exploit for CVE-2024-39621?
Yes, there are known exploitation methods for CVE-2024-39621 that leverage the path traversal vulnerability.