Impact
Contributors discovered that uListing versions up to 2.2.0 contain a broken access control flaw. The flaw allows an attacker to execute functions that should be restricted to authorized users. If exploited, the attacker could modify listings, delete content, or otherwise manipulate the site’s data, thereby compromising data integrity and possibly enabling further privilege escalation.
Affected Systems
Stylemix uListing plugin for WordPress, all installations running version 2.2.0 or earlier.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is web-based, through the WordPress interface or exposed API endpoints, and requires authentication or privilege escalation to fully exploit. Without an official patch or workaround, the risk remains that an attacker with access to the plugin can perform unauthorized operations.
OpenCVE Enrichment