Description
Subscriber Broken Access Control in uListing <= 2.2.0 versions.
Published: 2026-07-23
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Stylemix uListing WordPress plugin contains a broken access control flaw in all releases up to and including version 2.2.0. The vulnerability specifically allows users who hold the subscriber role to reach or modify data and functionality that should be restricted to higher‑level roles such as administrators. This can lead to unauthorized changes to listings, deletion of content, or extraction of sensitive information stored by the plugin, presenting a risk to confidentiality, integrity, and availability of site data. The weakness is classified as CWE-862, Incorrect Privilege Assignment.

Affected Systems

WordPress sites that have the Stylemix uListing plugin installed with a release version of 2.2.0 or earlier are impacted. The plugin operates within the WordPress content management system, and any site using these versions is vulnerable regardless of other configuration.

Risk and Exploitability

The vulnerability has a CVSS score of 5.4, indicating moderate severity, and an EPSS score of less than 1%, suggesting a very low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated attacker possessing a valid subscriber account on the affected WordPress site, most likely through the plugin’s front‑end or administrative interface where role checks are bypassed. Given the low EPSS and moderate CVSS, the risk is considered moderate, but unauthorized access to privileged functionality can have significant operational impact.

Generated by OpenCVE AI on August 3, 2026 at 22:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the uListing plugin to any release newer than 2.2.0 to eliminate the access‑control flaw.
  • If the plugin is not essential for your site, remove or permanently disable it to eliminate the attack surface.
  • As a temporary measure, restrict subscriber permissions for plugin‑specific features by adding custom role limitations or through a security plugin that enforces stricter access controls until a proper update can be applied.

Generated by OpenCVE AI on August 3, 2026 at 22:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Stylemixthemes
Stylemixthemes ulisting
Wordpress
Wordpress wordpress
Vendors & Products Stylemixthemes
Stylemixthemes ulisting
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in uListing <= 2.2.0 versions.
Title WordPress uListing plugin <= 2.2.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Stylemixthemes Ulisting
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T13:34:05.961Z

Reserved: 2026-02-19T09:52:03.312Z

Link: CVE-2026-27391

cve-icon Vulnrichment

Updated: 2026-07-23T13:34:00.307Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:17:18.153

Modified: 2026-07-23T14:17:11.457

Link: CVE-2026-27391

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:45:04Z

Weaknesses