CVE-2024-39622: WordPress ListingPro theme <= 2.9.4 - Unauthenticated SQL Injection vulnerability
Published Aug 29, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro allows SQL Injection.This issue affects ListingPro: from n/a through <= 2.9.4.
Affected Software
1 affected component
Cridio Listingpro Wordpress<=2.9.4
Event History
Aug 29, 2024
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-39622?
CVE-2024-39622 is rated as a high severity vulnerability due to its potential for SQL injection.
2
How do I fix CVE-2024-39622?
To mitigate CVE-2024-39622, update the CridioStudio ListingPro theme to version 2.9.5 or later.
3
What types of attacks are possible with CVE-2024-39622?
CVE-2024-39622 enables attackers to perform unauthorized SQL queries leading to data theft or manipulation.
4
Which versions of ListingPro are affected by CVE-2024-39622?
CVE-2024-39622 affects ListingPro versions from n/a to 2.9.4.
5
Is authentication required to exploit CVE-2024-39622?
No, CVE-2024-39622 is an unauthenticated SQL injection vulnerability, allowing exploitation without user login.