Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.1

CridioStudio ListingPro Plugin Allows Malicious Scripts in Web Pages

CVE-2026-28122
Summary

A security flaw in the ListingPro plugin for CridioStudio allows hackers to inject malicious scripts into web pages, potentially stealing user data or taking control of their accounts. This affects all versions of ListingPro up to 2.9.8. Update the plugin to the latest version to fix this issue.

Original title
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro listingpro-plugin allows Reflected XSS.This issue affects ListingPro: f...
Original description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro listingpro-plugin allows Reflected XSS.This issue affects ListingPro: from n/a through <= 2.9.8.
nvd CVSS3.1 7.1
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026