CVE-2024-39623: WordPress ListingPro theme <= 2.9.4 - Cross Site Request Forgery (CSRF) to Account Takeover vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in CridioStudio ListingPro listingpro allows Authentication Bypass.This issue affects ListingPro: from n/a through <= 2.9.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39623?
CVE-2024-39623 is a critical vulnerability that allows authentication bypass through Cross-Site Request Forgery (CSRF) in ListingPro before version 2.9.4.
How do I fix CVE-2024-39623?
To fix CVE-2024-39623, update CridioStudio ListingPro to version 2.9.5 or above.
What versions of ListingPro are affected by CVE-2024-39623?
CVE-2024-39623 affects all versions of CridioStudio ListingPro up to and including version 2.9.4.
What are the potential consequences of CVE-2024-39623?
Exploiting CVE-2024-39623 could allow attackers to bypass authentication and potentially take over user accounts.
Is CVE-2024-39623 related to other vulnerabilities?
CVE-2024-39623 is a specific vulnerability and should be evaluated separately, but it highlights the importance of securing against CSRF attacks.