S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Sep 24, 2025

CVE-2020-36723 Scanner

CVE-2020-36723 Scanner - Sensitive Data Exposure vulnerability in ListingPro

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-36723
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6.1 via the ~/listingpro-plugin/functions.php file. This makes it possible for unauthenticated attackers to extract sensitive data including usernames, full names, email addresses, phone numbers, physical addresses and user post counts.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ListingPro - WordPress Directory & Listing Themeby n/a
AFFECTED< 2.6.1SAFE ✓≥ 2.6.1
Updated Aug 21, 2026View on NVD →
Detail

ListingPro is a popular WordPress theme used for creating directory and listing websites. It is widely employed by businesses and individuals wishing to maintain a local or global directory. The theme provides extensive features, making it suitable for a range of industries seeking an online presence. Users leverage ListingPro to handle business listings, reviews, and ratings. Due to its widespread use, vulnerabilities within ListingPro can impact a considerable number of sites. The installation of plugins like ListingPro is typically done by webmasters, developers, or site owners aiming for robust directory functions.

The sensitive data exposure vulnerability in ListingPro affects its functionality by allowing unauthenticated users to obtain sensitive user information. Exploiting the vulnerability could lead to unauthorized dissemination of usernames, email addresses, physical addresses, and more. Sensitive data exposure is a critical concern as it compromises user privacy and might lead to security threats such as identity theft. The issue is present in versions of ListingPro less than 2.6.1, and users of the theme should upgrade to mitigate risks. By understanding and patching this vulnerability, site administrators can prevent unauthorized access to sensitive information.

The vulnerability resides in the ~/listingpro-plugin/functions.php file, which, in affected versions, can improperly handle data. Attackers can craft requests to the vulnerable endpoint to retrieve personal information. The attack vector is a GET request sent to the '/wp-admin/index.php?download-lp-users=yes' endpoint. This endpoint, when exploited, reveals user-related details such as names and emails without authentication. The theme's inability to secure this endpoint underscores poor data handling practices in its design.

Exploiting this vulnerability could result in data breaches and privacy violations. Attackers could gather sensitive information for malicious purposes, such as social engineering attacks or targeted phishing campaigns. Website users affected by this exposure might experience increased spam or identity theft risks. Administrators could face reputational damage and potential legal consequences if protective measures are not implemented. Therefore, addressing this vulnerability is paramount to safeguarding user data and maintaining trust.

REFERENCES

Solution Advice
  • Update ListingPro theme to version 2.6.1 or later to mitigate the vulnerability.
  • Review current user permissions and ensure that only necessary information is accessible to public endpoints.
  • Implement access control mechanisms for sensitive data to limit exposure to authorized users.
  • Conduct regular security audits to assess plugin vulnerabilities and ensure compliance with security best practices.
  • Educate your team and users about potential risks associated with sensitive data exposure and how to recognize phishing scams.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.