Impact
The WPAdverts – Classifieds Plugin fails to enforce the required authorization checks on its classifieds-types REST endpoint, creating a broken access control flaw identified as CWE-862. As a result, any user—authenticated or not—can send a request to this endpoint and retrieve a wide range of internal site configuration data, such as registered post types, taxonomies, form schemas, contact options, and custom field meta keys. Retrieving this information constitutes a sensitive information disclosure that could be leveraged to plan more targeted attacks against the WordPress site.
Affected Systems
WordPress installations running the WPAdverts – Classifieds Plugin with a version of 2.3.2 or earlier. These sites permit unauthenticated consumers to query the compromised REST endpoint, exposing the listed configuration data.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5, indicating high severity. The EPSS score is not provided, and the issue is not listed in CISA's KEV catalog. An attacker can exploit the weakness simply by issuing an HTTP request to the classifieds-types REST endpoint from any location, without needing credentials. This leads to direct disclosure of sensitive configuration data and may aid attackers in mounting further attacks.
OpenCVE Enrichment