Impact
The flaw is a broken access control vulnerability in the WordPress Classified Listing plugin up to version 5.4.2. It allows an authenticated user with subscriber privileges to view, modify, or delete listings that should be restricted to higher‑privileged roles. This defect can be used to tamper with or delete legitimate listings, potentially leading to defacement, fraud, or disruption of the site’s content integrity.
Affected Systems
RadiusTheme:Classified Listing plugin versions <= 5.4.2 are affected. Any WordPress site that has installed these releases must verify the plugin version and apply an update if the plugin is present.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. A very low EPSS score (<1%) suggests that exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, attackers must first possess a subscriber account or successfully create one, so the attack vector is the web application with an existing user session. Once the attacker controls such an account, they can create, edit, or delete listings without proper authorization.
OpenCVE Enrichment