Impact
Based on the description, the vulnerability resides in the Classified Listing WordPress plugin prior to version 5.4.4. The plugin does not perform a capability check on an AJAX action that returns aggregated store revenue totals, enabling users with contributor-level access and above to read daily revenue figures normally restricted to administrators and report managers. This information‑disclosure weakness, mapped to CWE-862, compromises the confidentiality of sensitive financial data for sites that use the plugin.
Affected Systems
Based on the description, the vulnerability affects any installation of the Classified Listing plugin for WordPress running a version older than 5.4.4. No specific vendor namespace is provided, so the impact applies universally to sites using this unpatched plugin version.
Risk and Exploitability
The vulnerability has a CVSS score of 2.7, indicating low severity, and an EPSS score of < 1%. It is not listed in the CISA KEV catalog, suggesting no publicly known exploitation yet. Because the flaw is tied to an authenticated AJAX endpoint and requires only contributor privileges—roles commonly granted to content authors—the risk of exploitation is moderate. Based on the description, it is inferred that an attacker who has or can obtain contributor access could trigger the endpoint and retrieve revenue data without advanced privileges.
OpenCVE Enrichment