Record summary

CVE-2020-36723 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6.1 via the ~/listingpro-plugin/functions.php file. This makes it possible for unauthenticated attackers to extract sensitive data including usernames, full names, email addresses, phone numbers, physical addresses and user post counts.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 27, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 28, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

ListingPro - WordPress Directory & Listing Theme

Default status: unaffected

CVE ListBefore 2.6.1affected

Nuclei templates

1
ProjectDiscoveryHIGHListingPro < 2.6.1 - Sensitive Data DisclosureCVSS 5.3

The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6.1 via the ~/listingpro-plugin/functions.php file. This makes it possible for unauthenticated attackers to extract sensitive data including usernames, full names, email addresses, phone numbers, physical addresses and user post counts.

Impact

Unauthenticated attackers can extract sensitive user data including usernames, email addresses, phone numbers, and physical addresses from all registered users.

Remediation

Upgrade to ListingPro version 2.6.1 or later.

WeaknessesCWE-200
Authorsritikchaddha
Template tagscvecve2020wordpresswp-pluginwpexposurelistingprovulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:cridio:listingpro:*:*:*:*:*:wordpress:*:*
FOFA: body="/wp-content/plugins/listingpro"

Source: ProjectDiscovery

References

4