Impact
The vulnerability is a Missing Authorization flaw that allows an adversary to exploit incorrectly configured access control security settings in the ListingPro WordPress plugin. By bypassing intended restriction mechanisms, an attacker can gain unauthorized access to protected listings, configuration information, or administrative functions, potentially compromising the confidentiality, integrity, and availability of the site’s data.
Affected Systems
The issue affects the CridioStudio ListingPro plugin version 2.9.8 and earlier. Any WordPress installation running this plugin before the 2.9.9 release is vulnerable; it is not limited to a specific hosting environment or user role according to the provided data.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity vulnerability, while the EPSS score of less than 1% suggests a very low probability of exploitation at the current time. The vulnerability is not listed in the CISA KEV catalog. Attackers would most likely attempt to leverage the web-based WordPress interface to reach the plugin’s administrative functions, although the precise attack vector is not detailed in the advisory. The lack of a known public exploit and low EPSS reduce immediate risk but the persistence of a broken access control flaw still warrants prompt remediation.
OpenCVE Enrichment
EUVD