Impact
This vulnerability is a missing authorization flaw in the ListingPro theme that allows attackers to access restricted functions without proper authentication. The flaw permits exploitation of incorrectly configured access control security levels, potentially giving an attacker the ability to view or modify protected content, elevate privileges, or otherwise compromise the integrity of the WordPress site. The weakness identified is CWE-862, highlighting that the application does not enforce required access controls for specific actions.
Affected Systems
CridioStudio ListingPro theme versions from the initial release through 2.9.9. Any site running the theme version 2.9.9 or earlier is impacted and requires attention.
Risk and Exploitability
The CVSS score of 5.3 places this vulnerability in the medium severity range. The EPSS score is below 1%, indicating a low estimated probability of exploitation at this time, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is via the web, where an attacker can send crafted requests to administrative endpoints that lack proper authorization checks.
OpenCVE Enrichment