Impact
Classified Pro, a WordPress theme, is vulnerable due to a missing capability check in the "cwp_addons_update_plugin_cb" function. Authenticated users with subscriber level access and higher can exploit this flaw to install arbitrary plugins on the site’s server. Installing such plugins can provide the attacker with remote code execution capabilities, enabling full compromise of the website.
Affected Systems
The vulnerability affects Cridio Studio’s ClassifiedPro reCommerce WordPress Theme in all releases up to and including version 1.0.14. Any site that has installed one of those versions is at risk.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity impact, while the EPSS score of < 1 % suggests that widespread exploitation is currently unlikely. This vulnerability is not yet listed in CISA’s KEV catalog. Attacking this flaw requires an authenticated session with at least subscriber permissions and knowledge of the nonce supplied by the CubeWP Framework plugin. Once the attacker gains plugin‑upload access, arbitrary code can be deployed on the server.
OpenCVE Enrichment