Impact
The Stylemix uListing WordPress plugin contains a broken access control flaw in all releases up to and including version 2.2.0. The vulnerability specifically allows users who hold the subscriber role to reach or modify data and functionality that should be restricted to higher‑level roles such as administrators. This can lead to unauthorized changes to listings, deletion of content, or extraction of sensitive information stored by the plugin, presenting a risk to confidentiality, integrity, and availability of site data. The weakness is classified as CWE-862, Incorrect Privilege Assignment.
Affected Systems
WordPress sites that have the Stylemix uListing plugin installed with a release version of 2.2.0 or earlier are impacted. The plugin operates within the WordPress content management system, and any site using these versions is vulnerable regardless of other configuration.
Risk and Exploitability
The vulnerability has a CVSS score of 5.4, indicating moderate severity, and an EPSS score of less than 1%, suggesting a very low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated attacker possessing a valid subscriber account on the affected WordPress site, most likely through the plugin’s front‑end or administrative interface where role checks are bypassed. Given the low EPSS and moderate CVSS, the risk is considered moderate, but unauthorized access to privileged functionality can have significant operational impact.
OpenCVE Enrichment