Impact
The vulnerability in the listingpro-reviews plugin is a missing authorization flaw that allows an attacker to bypass incorrectly configured access control security levels. Without proper access checks, a malicious actor can potentially view, modify, or delete review data and other sensitive information exposed by the plugin. This breach can compromise data confidentiality, integrity, and availability within the affected WordPress site.
Affected Systems
The flaw affects the CridioStudio ListingPro Reviews plugin for WordPress, specifically all releases from the earliest available version up to, but not including, 2.9.11. Users running any of these versions should verify which version they have installed.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity level, and the EPSS score of less than 1% suggests that exploitation is currently unlikely. The plugin is not listed in the CISA KEV catalog, indicating no publicly known exploitation at this time. Analysts infer that the attack vector is via the web interface of the plugin, exploiting the missing authorization checks that would be triggered by crafted HTTP requests or by directly accessing privileged endpoints without proper validation.
OpenCVE Enrichment
EUVD