Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro Reviews listingpro-reviews allows Reflected XSS.This issue affects ListingPro Reviews: from n/a through < 2.9.11.
Published: 2026-01-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Upgrade Theme
AI Analysis

Impact

The ListingPro Reviews theme does not properly neutralize user input that is then rendered into a web page, creating a reflected XSS vulnerability. Attacker‑controlled data entered into certain fields can be echoed back into the site’s HTML, making the browser execute arbitrary JavaScript in the victim’s context. The description indicates the possibility of hijacking user sessions, stealing data, or modifying page content, but these are inferred impacts based on typical XSS consequences and are not explicitly stated in the supplied description.

Affected Systems

All versions of the CridioStudio ListingPro Reviews WordPress theme up to, but not including, 2.9.11 are vulnerable. This includes version 1.7 and all earlier releases, as well as every 2.x release prior to 2.9.11.

Risk and Exploitability

The CVSS base score of 7.1 signals a high risk level. The EPSS score of less than 1 percent suggests that wild exploitation is unlikely at present, and the vulnerability is not listed in CISA KEV. The flaw is reflected and can be triggered by a web‑based attack vector, such as a crafted URL or form payload that is echoed back to the browser; this inference comes from the term 'Reflected XSS' used in the description and does not explicitly detail the attack vector. Exploitation would require a victim to load the vulnerable page, making it potentially possible against both unauthenticated and authenticated users depending on where the affect user input is processed.

Generated by OpenCVE AI on April 29, 2026 at 00:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch by upgrading ListingPro Reviews to version 2.9.11 or newer.
  • If an immediate update is not possible, disable or uninstall the theme to eliminate the vulnerable code.
  • Implement a web application firewall or security plugin that filters or blocks reflected XSS payloads as a temporary safeguard until a permanent patch is applied.

Generated by OpenCVE AI on April 29, 2026 at 00:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro Reviews listingpro-reviews allows Reflected XSS.This issue affects ListingPro Reviews: from n/a through <= 1.7. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro Reviews listingpro-reviews allows Reflected XSS.This issue affects ListingPro Reviews: from n/a through < 2.9.11.

Wed, 28 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 27 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro Reviews listingpro-reviews allows Reflected XSS.This issue affects ListingPro Reviews: from n/a through <= 1.7.
Title WordPress ListingPro Reviews theme <= 1.7 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:36:18.569Z

Reserved: 2025-12-29T11:18:51.165Z

Link: CVE-2025-69051

cve-icon Vulnrichment

Updated: 2026-01-27T15:35:52.416Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:18.613

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-69051

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T01:00:11Z

Weaknesses