CVE-2026-39438CRITICAL NVDCVSS Score 9.3Severity CRITICALPublished Jun 17, 2026Vendor unknownDescriptionUnauthenticated SQL Injection in ListingPro <= 2.9.10 versions.Referenceshttps://patchstack.com/database/wordpress/plugin/listingpro-plugin/vulnerability/wordpress-listingpro-plugin-2-9-10-sql-injection-vulnerability?_s_id=cve