CVE-2025-12577
Description
The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/listar/v1/place/save' REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update listing details.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
WordPress Listar plugin has a missing capability check on a REST API endpoint, allowing subscribers to modify listing details.
The Listar – Directory Listing & Classifieds WordPress Plugin is vulnerable to unauthorized data modification due to a missing capability check on the /wp-json/listar/v1/place/save REST API endpoint. This affects all versions up to and including 3.0.0. The endpoint lacks proper authorization, allowing authenticated users with Subscriber-level access or above to update listing details without the required permissions [1].
An attacker who is authenticated as a Subscriber or higher can send crafted requests to the /wp-json/listar/v1/place/save endpoint. Since there is no capability check, the request is processed and modifies listing data. No additional privileges or complex conditions are needed beyond a valid WordPress account [1].
Successful exploitation allows an authenticated attacker to alter any listing details within the plugin. This could include changing titles, descriptions, prices, contact information, or other fields, potentially leading to misinformation, fraudulent listings, or reputational damage to legitimate listing owners [1].
The plugin has been closed on the WordPress plugin repository as of December 4, 2025, and is no longer available for download. Users are advised to remove or replace the plugin, as no official patch has been released [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.