Impact
The vulnerability is a missing authorization flaw in the Classified Listing plugin for WordPress that allows an attacker to bypass intended access controls. This Broken Access Control issue can enable unauthorized users to perform privileged operations that should be restricted. The weakness matches CWE-862, which identifies improper enforcement of access permissions.
Affected Systems
The flaw affects installations of RadiusTheme Classified Listing version 5.0.6 and earlier. Users running an impacted WordPress site with this plugin must review their current version and assess whether it falls within the vulnerable range.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score of less than 1% suggests exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. Because the description does not explicitly state how the flaw is triggered, it is inferred that the likely attack vector is a user with the ability to submit content or manage listings, potentially bypassing normal permission checks to gain elevated access.
OpenCVE Enrichment
EUVD