Impact
The vulnerability is a missing authorization flaw that allows an attacker to perform actions within the ListingHub plugin that should be restricted to privileged users. Because the plugin does not enforce proper access controls, a malicious actor can potentially read, modify, or delete listing information, leading to confidentiality and integrity breaches. This weakness aligns with CWE-862, which categorizes improper authorization as a critical security flaw.
Affected Systems
Affects e-plugins ListingHub, any WordPress site running ListingHub version 1.2.7 or earlier. No additional version details are supplied, so any installation of the plugin in this range is at risk.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity, while the EPSS score of less than 1% suggests a low but non‑zero probability of exploitation in the wild. The vendor has not listed this flaw in CISA’s KEV catalog. Based on the description, it is inferred that exploitation could involve sending crafted HTTP requests to the plugin’s endpoints, and that the flaw can be abused with minimal prerequisites—no privileged server access or WordPress administrator account is required. It is also inferred that the low EPSS reduces the likelihood of immediate widespread attacks, but the high CVSS still warrants prompt remediation.
OpenCVE Enrichment