Impact
The vulnerability is a missing authorization check in the ListingPro theme that permits a user with insufficient permissions to perform operations normally restricted to higher privileges. This flaw can enable an attacker to modify or delete listings, alter presentation settings, or otherwise change site content without proper authorization. The weakness is associated with CWE‑862, indicating inadequate role‑based access control.
Affected Systems
Affected products are the CridioStudio ListingPro theme for WordPress, and all released versions up to and including 2.9.9. Users running any of these versions are potentially exposed.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, further indicating limited known exploitation. The likely attack vector requires access to a WordPress account with some privileges or a website where the theme is installed, after which an attacker could abuse the broken access control to alter content or settings. Because the flaw involves an access control misconfiguration, it is best mitigated by applying the vendor’s patch or upgrading to an unaffected version.
OpenCVE Enrichment