Impact
The vulnerability resides in the ListingPro WordPress plugin, allowing users with only subscriber privileges to bypass access controls; based on the description, it is inferred that this may grant them access to content and metadata that should be restricted to administrators or authors. This flaw could compromise confidentiality if sensitive listing information or user data is exposed. The weakness is a classic access control error, catalogued as CWE‑862.
Affected Systems
Any WordPress site running ListingPro plugin version 2.9.10 or earlier is impacted. Sites that rely on default role permissions and have not upgraded beyond 2.9.10 could potentially expose private listings to all registered subscribers, based on the inferred impact of the access control flaw.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium-level severity, while the EPSS score of less than 1% suggests that the likelihood of exploitation remains low at present. The vulnerability is not yet listed in CISA’s KEV database. An attacker with the ability to create or gain a subscriber account—whether exploited directly or via other vulnerabilities—could use this flaw to access confidential content. The required conditions are minimal, as the flaw is triggered by a standard role permissions check within the plugin.
OpenCVE Enrichment