Impact
A missing authorization check allows an attacker to bypass normal access controls and perform actions that should be restricted to privileged users. The vulnerability, identified as a CWE-862 Broken Access Control, could enable unauthorized manipulation of data, configuration settings, or the execution of privileged functions within the WordPress site using the ListingPro theme.
Affected Systems
CridioStudio ListingPro theme for WordPress, in all releases prior to version 2.9.10. Any WordPress installation using a ListingPro theme version older than 2.9.10 is affected, regardless of other configuration.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑impact vulnerability, but the EPSS score of less than 1% suggests a low likelihood of immediate exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could exploit the flaw by issuing crafted HTTP requests to endpoints that should be protected, potentially without authentication or with minimal privileges, thereby gaining elevated access to the site.
OpenCVE Enrichment