Access violation vulnerability in ListingPro – WordPress Directory & Listing Theme 2.6.1

The ListingPro – WordPress Directory & Listing Theme for WordPress has a security flaw in earlier versions before 2.6.1. This flaw means that anyone, even without logging in, can install, activate and deactivate any plugin they want. This is because the lp_cc_addons_actions function does not check if the user has the right permissions. This could cause security issues. To fix this, make sure you have the latest version of ListingPro installed (2.6.1 or later).

Detected in:

ListingPro - WordPress Directory & Listing Theme open vulnerable versions: >= * < 2.6.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.