ListingPro - WordPress Directory & Listing Theme

ListingPro - WordPress Directory & Listing Theme has 15 disclosed vulnerabilities in the WordSec catalog, reported between 2019 and 2026; 13 are fixed and 2 remain unpatched as of September 2026. Their average CVSS score is 6.7, and the most serious one scores 10.0 out of 10. Severity breakdown: 2 critical and 3 high. 2025 was the busiest year with 5 disclosures.

The most common weakness is Cross-Site Scripting, behind 6 of the records (40%). Other recurring categories include Missing Authorization, PHP Remote File Inclusion.

13 of the records (87%) have a vendor fix, while 2 remain unpatched. The oldest unresolved one dates back to 2025.

6 independent researchers contributed these findings, most of them (6) reported by Rafie Muhammad.

01234567891029.11.2019Today29.11.20195.4ListingPro - WordPress Directory & Listing Theme < 2.0.14.5 - Stored Cross-Site Scripting CVSS 5.4 · 29.11.20196.1ListingPro - WordPress Directory & Listing Theme < 2.0.14.5 - Reflected Cross-Site Scripting CVSS 6.1 · 29.11.20195.4ListingPro - WordPress Directory & Listing Theme < 2.0.14.5 - Stored Cross-Site Scripting CVSS 5.4 · 29.11.201915.01.20206.1ListingPro - WordPress Directory & Listing Theme < 2.5.4 - Cross-Site Scripting CVSS 6.1 · 15.01.202017.12.20209.8ListingPro - WordPress Directory & Listing Theme < 2.6.1 - Arbitrary Plugin Installation, Activation and Deactivation CVSS 9.8 · 17.12.20205.3ListingPro - WordPress Directory & Listing Theme < 2.6.1 - Sensitive Information Disclosure CVSS 5.3 · 17.12.202022.07.20248.8ListingPro <= 2.9.4 - Authenticated (Subscriber+) Local File Inclusion CVSS 8.8 · 22.07.20248.8ListingPro <= 2.9.4 - Cross-Site Request Forgery to Account Takeover CVSS 8.8 · 22.07.202410.0ListingPro <= 2.9.4 - Unauthenticated SQL Injection CVSS 10.0 · 22.07.202412.09.20258.1ListingPro < 2.9.10 - Unauthenticated Local File Inclusion CVSS 8.1 · 12.09.20256.1ListingPro < 2.9.10 - Reflected Cross-Site Scripting CVSS 6.1 · 12.09.20254.3ListingPro < 2.9.10 - Missing Authorization CVSS 4.3 · 12.09.202519.10.20255.3ListingPro <= 2.9.9 - Missing Authorization CVSS 5.3 · 19.10.202506.11.20254.3ListingPro <= 2.9.9 - Missing Authorization CVSS 4.3 · 06.11.202524.06.20266.4ListingPro - WordPress Directory & Listing Theme <= 2.9.11 - Authenticated (Subscriber+) Stored Cross-Site Scripting CVSS 6.4 · 24.06.2026

Strategic Overview

Avg CVSSMedium
6.7/ 10
Patch Coverage87%
Open

2

Fixed

13

Get automatic notifications for all ListingPro - WordPress Directory & Listing Theme vulnerabilities before they are exploited.

Most severe open issueCVSS 5.3CVE-2025-63047

ListingPro <= 2.9.9 - Missing Authorization

Read the full analysis

Vulnerability Records

15 records
2026-06-24 00:00CVE-2026-56046
6.4
Medium
darooYes
2025-11-06 00:00CVE-2025-63039
4.3
Medium
Denver JacksonNo
2025-10-19 00:00CVE-2025-63047
5.3
Medium
João Pedro Soares de AlcântaraNo
2025-09-12 00:00CVE-2025-64377
8.1
High
Rafie MuhammadYes
2025-09-12 00:00CVE-2025-64376
6.1
Medium
Rafie MuhammadYes
2025-09-12 00:00CVE-2025-64378
4.3
Medium
Rafie MuhammadYes
2024-07-22 00:00CVE-2024-39624
8.8
High
Rafie MuhammadYes
2024-07-22 00:00CVE-2024-39623
8.8
High
Rafie MuhammadYes
2024-07-22 00:00CVE-2024-39622
10.0
Critical
Rafie MuhammadYes
2020-12-17 00:00CVE-2020-36719
9.8
Critical
Jerome BruandetYes
Showing 1–10 of 15 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C