N/A
2026-04-21< 2.9.11
ListingPro Plugin <= 2.9.10 - Unauthenticated SQL Injection
Minimum safe version
2.9.11
Update to 2.9.11 or later to address 5 fixable vulnerabilities
ListingPro Plugin <= 2.9.10 - Unauthenticated SQL Injection
CVE-2026-28122
CVE-2025-63046
WordPress ListingPro plugin <= 2.9.8 - Broken Access Control vulnerability
CVE-2024-38795
CVE-2024-39621
CVE-2024-39620
CVE-2024-39619