Impact
The HivePress Claim Listings WordPress plugin contains a missing authorization flaw that lets an unauthenticated or underprivileged user interact with claim listing functions. The weakness allows attackers to view or alter claim data without proper permission checks, potentially exposing sensitive information and corrupting listings. The vulnerability falls under the access control category (CWE-862).
Affected Systems
All WordPress installations using the HivePress Claim Listings plugin with a version through 1.1.3 are affected. The plugin applies to a wide range of sites that rely on HivePress for managing user‑generated listings, and any installation that has not upgraded beyond 1.1.3 remains vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score is below 1 %, suggesting that few attacks are expected. Because the flaw hinges on an improper authorization check, exploitation would require targeting specific claim listing URLs, and it does not necessitate elevated local privileges. With no known public exploits and the vulnerability not in CISA’s KEV catalog, the immediate risk is low, but a targeted attacker could exploit it to gain unauthorized access to claim listings.
OpenCVE Enrichment
EUVD