Impact
The vulnerability is a missing authorization issue that allows attackers to access WP‑Lister Lite for eBay plugin functionality without the required user permissions. This can lead to unauthorized management of eBay listings, potential manipulation of product data, or other privileged actions that could compromise the confidentiality or integrity of the site’s content. The weakness is described by CWE‑862.
Affected Systems
WordPress sites that have the WP Lab WP‑Lister Lite for eBay plugin installed, with versions up to and including 3.8.5. Any WordPress installation using those plugin versions is potentially affected.
Risk and Exploitability
The vulnerability scores a 5.3 on the CVSS, indicating medium severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation at present. It is not listed in the CISA KEV catalog, so no publicly known exploits have been reported. Based on the description, the likely attack vector is a web‑based compromise through the plugin’s administrative interface, where an attacker could exploit the incorrectly configured access control to elevate privileges or perform unauthorized actions.
OpenCVE Enrichment