Description
The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. This is due to the plugin allowing users who are registering new accounts to set their own role by supplying the 'listing_user_role' parameter. This makes it possible for unauthenticated attackers to gain elevated privileges by registering an account with the administrator role.
Published: 2026-02-19
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker who has no existing credentials to register a new account by supplying the 'listing_user_role' parameter and assigning the highest available role. This results in the account gaining full administrator privileges, providing the attacker complete control over the WordPress site including content, settings, and other users.

Affected Systems

The affected product is the SmartDataSoft Clasifico Listing WordPress plugin, all released versions up to and including 2.0 are impacted.

Risk and Exploitability

The CVSS score of 9.8 marks it as critical, and although the EPSS score is under 1% and it is not current in the CISA KEV catalog, the flaw is exploitable with no authentication required. An attacker only needs to craft a registration request containing the privileged role parameter to create an admin user and gain privileged access.

Generated by OpenCVE AI on April 21, 2026 at 15:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the plugin to a version newer than 2.0 where the role selection during registration is removed.
  • If an upgrade is not immediately possible, disable new user registrations or strip the 'listing_user_role' parameter from the signup process so that unauthenticated users cannot influence their role.
  • Audit the site’s user accounts for any administrator accounts that may have been created through the exploit and remove or reassign them as needed.

Generated by OpenCVE AI on April 21, 2026 at 15:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 20 Feb 2026 01:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 19 Feb 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Smartdatasoft
Smartdatasoft clasifico Listing
Wordpress
Wordpress wordpress
Vendors & Products Smartdatasoft
Smartdatasoft clasifico Listing
Wordpress
Wordpress wordpress

Thu, 19 Feb 2026 04:15:00 +0000

Type Values Removed Values Added
Description The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. This is due to the plugin allowing users who are registering new accounts to set their own role by supplying the 'listing_user_role' parameter. This makes it possible for unauthenticated attackers to gain elevated privileges by registering an account with the administrator role.
Title Clasifico Listing <= 2.0 - Unauthenticated Privilege Escalation
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Smartdatasoft Clasifico Listing
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:00:28.424Z

Reserved: 2025-11-07T16:19:24.522Z

Link: CVE-2025-12882

cve-icon Vulnrichment

Updated: 2026-02-19T17:28:43.372Z

cve-icon NVD

Status : Deferred

Published: 2026-02-19T07:17:29.113

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-12882

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T16:00:13Z

Weaknesses