Plugin Vulnerability Hub
Plugin 4 known issues Latest disclosed Apr 03, 2026

Listeo-Core - Directory Plugin by Purethemes Vulnerabilities

Review known vulnerability records for the WordPress plugin Listeo-Core - Directory Plugin by Purethemes (`listeo-core`), including severity, CVE references, affected versions, and patch status.

Known Records
4
High or Critical
0
Linked CVEs
4
Last Updated
Apr 04, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Listeo-Core - Directory Plugin by Purethemes so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
4 records include a published patch path.
Severity Mix
0 critical and 0 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for Listeo-Core - Directory Plugin by Purethemes

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2025-14938
Listeo-Core - Directory Plugin by Purethemes <= 2.0.27 - Unauthenticated Arbitrary Media Upload

The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and including, 2.0.27 via the "listeo_core_handle_dropped_media" function. This is due to missing authorization and capability checks on the AJAX endpoint handling...

Published
Apr 03, 2026
Patched Release
2.0.28
Affected Versions
Versions up to 2.0.27
Next Step
Update to 2.0.28 or newer if supported.
Plugin Medium Patched: No CVE-2026-25461
Listeo-Core - Directory Plugin by Purethemes <= 2.0.21 - Reflected Cross-Site Scripting

The Listeo-Core - Directory Plugin by Purethemes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to injec...

Published
Mar 17, 2026
Patched Release
Not published
Affected Versions
Versions up to 2.0.21
Next Step
Open the full report for remediation notes and references.
Plugin Medium Patched: Yes CVE-2025-67932
Listeo Core < 2.0.19 - Reflected Cross-Site Scripting

The Listeo Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 2.0.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

Published
Jan 06, 2026
Patched Release
2.0.19
Affected Versions
Versions before 2.0.19
Next Step
Update to 2.0.19 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-49404
Listeo-Core < 2.0.7 - Authenticated (Subscriber+) SQL Injection

The Listeo-Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and excluding, 2.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers...

Published
Aug 20, 2025
Patched Release
2.0.7
Affected Versions
Versions before 2.0.7
Next Step
Update to 2.0.7 or newer if supported.