Impact
The vulnerability is a missing authorization flaw (CWE‑862) in WP‑Lab’s WP‑Lister Lite for eBay plugin that permits exploitation of incorrectly configured access controls. An attacker could gain unauthorized access to features such as viewing or managing eBay listings through the WordPress admin interface, effectively bypassing intended permission restrictions.
Affected Systems
The issue affects WP‑Lister Lite for eBay plugin releases from the earliest version through 3.8.3. Any WordPress site installing one of these plugin versions is vulnerable, irrespective of the underlying WordPress core edition.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact, while the EPSS score of < 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, so no documented exploits are currently known. The flaw is accessed via the WordPress admin area, but the description does not detail specific prerequisites for exploitation.
OpenCVE Enrichment