Impact
The vulnerability allows authenticated users with Subscriber-level access or higher to alter the custom fields of the Ultimate Classified Listings WordPress plugin. This occurs because the save_custom_fields function performs no capability check, enabling data tampering and potentially disruptive configuration changes. The weakness is a classic lack of authorization, listed as CWE-862.
Affected Systems
This issue affects the Ultimate Classified Listings plugin from webcodingplace, in all versions up to and including 1.7. Users running these versions on any WordPress installation are exposed.
Risk and Exploitability
The CVSS score of 4.3 reflects a moderate severity, while an EPSS score of <1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation activity. The attack vector is inferred to be through legitimate authenticated access by users with Subscriber or higher roles, as no additional conditions are described in the data.
OpenCVE Enrichment
EUVD