Description
Missing Authorization vulnerability in Property Hive PropertyHive propertyhive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through <= 2.1.12.
Published: 2025-12-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the Property Hive WordPress plugin that allows attackers to bypass incorrect or missing access control checks. This broken access control enables the exploitation of privileged operations or the exposure of sensitive content that should have been protected by the plugin’s security model. The flaw does not provide immediate remote code execution, but it can grant unauthorized users permissions to perform actions they should not be allowed to carry out. The weakness is classified as CWE-862, indicating an absence of proper authorization enforcement in the code.

Affected Systems

WordPress sites that have the Property Hive plugin installed with a version of 2.1.12 or earlier are affected. These installations expose their protected features or data through the plugin’s functionality and do not restrict access based on the required user roles or permissions.

Risk and Exploitability

The CVSS score of 7.5 classifies the issue as high severity, while the EPSS score of less than 1% indicates a very low probability of exploitation at the time of this assessment. The vulnerability is not currently listed in the CISA KEV catalog, which suggests that there is no confirmed widespread exploitation of this flaw. Attackers would need to target a WordPress site running the vulnerable plugin, craft requests that hit protected plugin endpoints, and leverage the missing authorization checks to gain unauthorized access. The attack vector is therefore remote, executed over the web interface of the affected site.

Generated by OpenCVE AI on April 29, 2026 at 18:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Property Hive plugin to version 2.1.13 or later, ensuring that any patch that corrects the missing authorization checks is applied.
  • If an immediate update is not feasible, disable or uninstall the plugin, or restrict its usage by removing it from active themes or user accounts that do not require access.
  • Conduct a comprehensive review of WordPress role and capability assignments, ensuring that least‑privilege principles are enforced and that plugin permissions are not over‑extended.

Generated by OpenCVE AI on April 29, 2026 at 18:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Propertyhive
Propertyhive propertyhive
Wordpress
Wordpress wordpress
Vendors & Products Propertyhive
Propertyhive propertyhive
Wordpress
Wordpress wordpress

Thu, 18 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Property Hive PropertyHive propertyhive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through <= 2.1.12.
Title WordPress PropertyHive plugin <= 2.1.12 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Propertyhive Propertyhive
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:16.407Z

Reserved: 2025-11-21T11:21:04.795Z

Link: CVE-2025-66088

cve-icon Vulnrichment

Updated: 2025-12-18T15:43:43.594Z

cve-icon NVD

Status : Deferred

Published: 2025-12-18T08:16:15.670

Modified: 2026-04-27T18:16:34.943

Link: CVE-2025-66088

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T19:00:06Z

Weaknesses