Impact
The vulnerability allows an attacker to invoke the AJAX action `acadp_public_custom_fields_listings` without authentication, thereby retrieving values of non‑public custom fields associated with listings. This exposure can include sensitive data such as financial information, personal identification, or location details that are intended for logged‑in users only. Because the data is delivered in plain form over the network, an adversary can read it directly, compromising confidentiality and potentially leading to identity theft or other privacy violations.
Affected Systems
WordPress sites that use the Advanced Classifieds & Directory Pro plugin version 3.4.2 or earlier are affected. The vulnerability impacts any installation of the plugin, regardless of the hosting environment or site configuration.
Risk and Exploitability
The vulnerability does not require authentication or complex input; an attacker simply sends a request to the public AJAX endpoint. The EPSS score is < 1%, indicating a very low but nonzero likelihood of active exploitation, and the CVSS score of 5.3 reflects a medium severity. The vulnerability is not listed in the CISA KEV catalog. Given the ease of exploitation and the privacy impact, the overall risk can be considered moderate, and administrators should treat the exposure as a significant issue until a fix is applied.
OpenCVE Enrichment