Description
WordPress Plugin ListingPro is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin ListingPro version 2.9.3 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable and remove the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Sermon Browser Multiple Cross-Site Scripting Vulnerabilities (0.45.15)
Oracle Database Server Improper Input Validation Vulnerability (CVE-2020-1953)
WordPress Plugin Easy Custom Auto Excerpt Cross-Site Scripting (2.4.6)
WordPress Plugin Post Views Counter Cross-Site Scripting (1.3.4)