Description
Incorrect Privilege Assignment vulnerability in e-plugins Hotel Listing hotel-listing allows Privilege Escalation.This issue affects Hotel Listing: from n/a through <= 1.4.0.
Published: 2025-12-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Hotel Listing WordPress plugin suffers from an incorrect privilege assignment flaw that allows authenticated users to obtain higher privileges than intended. This vulnerability, classified as CWE-266, lets a user who can log into the site acquire additional capabilities, such as editing or deleting hotel listings or accessing administrative settings that should normally require higher levels of authorization. The flaw arises from the plugin’s failure to enforce proper capability checks, resulting in over‑privileged roles within the WordPress installation.

Affected Systems

The flaw exists in all versions of the e-plugins Hotel Listing plugin up through version 1.4.0. The CVE description explicitly lists affected versions as “from n/a through <= 1.4.0”, indicating that any release prior to and including 1.4.0 contains the defect, while versions beyond 1.4.0 have not been identified as affected by the CVE. No fix version is stated in the advisory, so the current state remains vulnerable if the plugin is on any of those releases.

Risk and Exploitability

The CVSS score of 8.8 denotes a high‑severity risk, and the EPSS score of less than 1 % suggests exploitation attempts are not widespread yet. The vulnerability is not listed in CISA’s KEV catalog. An attacker who is able to authenticate to the site can leverage the flaw to assume roles with elevated permissions. The most likely attack vector is an authenticated local exploitation through the plugin’s administrative interface, where the privileged escalation is triggered by the plugin’s internal logic.

Generated by OpenCVE AI on May 1, 2026 at 06:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or uninstall the Hotel Listing plugin until an update that resolves the privilege assignment flaw is released.
  • If an updated release becomes available, upgrade the plugin after verifying that the fix removes the incorrect capability assignment logic, ensuring the plugin no longer grants excessive privileges.
  • Audit WordPress user roles and capabilities to confirm that no accounts possess unnecessary or elevated permissions that could be abused through the plugin.

Generated by OpenCVE AI on May 1, 2026 at 06:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 18 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in e-plugins Hotel Listing hotel-listing allows Privilege Escalation.This issue affects Hotel Listing: from n/a through <= 1.4.0.
Title WordPress Hotel Listing plugin <= 1.4.0 - Privilege Escalation vulnerability
Weaknesses CWE-266
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:47.021Z

Reserved: 2025-09-03T12:43:12.584Z

Link: CVE-2025-58710

cve-icon Vulnrichment

Updated: 2025-12-18T18:16:21.866Z

cve-icon NVD

Status : Deferred

Published: 2025-12-18T08:15:57.247

Modified: 2026-04-27T19:16:14.853

Link: CVE-2025-58710

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T06:15:10Z

Weaknesses