VYPR
Medium severity5.4NVD Advisory· Published Sep 26, 2025· Updated Apr 23, 2026

CVE-2025-60103

CVE-2025-60103

Description

Missing Authorization vulnerability in CridioStudio ListingPro listingpro-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingPro: from n/a through <= 2.9.8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in WordPress ListingPro plugin up to v2.9.8 allows unprivileged attackers to exploit incorrectly configured access controls.

Vulnerability

Overview

CVE-2025-60103 is a Missing Authorization vulnerability in the WordPress ListingPro plugin (listingpro-plugin) by CridioStudio, affecting versions from n/a through 2.9.8. The issue stems from an incorrectly configured access control security level, which allows functions to execute without proper authorization checks, such as missing nonce tokens or capability validation [1].

Exploitation

Details

The vulnerability can be exploited by an unauthenticated or low-privileged attacker who can send crafted requests to the affected plugin endpoints. Since the access control is broken, the plugin fails to verify whether the user has the necessary privileges to trigger certain higher-privileged actions. This type of flaw is commonly leveraged in mass-exploit campaigns targeting thousands of websites simultaneously [1].

Impact

An attacker successfully exploiting this vulnerability could perform unauthorized actions that should be restricted to higher-privileged users. Depending on the misconfigured functions, this might include modifying plugin settings, accessing sensitive data, or performing administrative operations. The CVSS v3 base score is 5.4 (Medium), reflecting the potential for significant site compromise [1].

Mitigation

The vendor has addressed this vulnerability in a subsequent release; users are strongly advised to update to the latest version of ListingPro. If immediate updating is not possible, temporary workarounds such as disabling the plugin or applying a web application firewall rule can help reduce risk [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.