CVE-2025-60103
Description
Missing Authorization vulnerability in CridioStudio ListingPro listingpro-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingPro: from n/a through <= 2.9.8.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in WordPress ListingPro plugin up to v2.9.8 allows unprivileged attackers to exploit incorrectly configured access controls.
Vulnerability
Overview
CVE-2025-60103 is a Missing Authorization vulnerability in the WordPress ListingPro plugin (listingpro-plugin) by CridioStudio, affecting versions from n/a through 2.9.8. The issue stems from an incorrectly configured access control security level, which allows functions to execute without proper authorization checks, such as missing nonce tokens or capability validation [1].
Exploitation
Details
The vulnerability can be exploited by an unauthenticated or low-privileged attacker who can send crafted requests to the affected plugin endpoints. Since the access control is broken, the plugin fails to verify whether the user has the necessary privileges to trigger certain higher-privileged actions. This type of flaw is commonly leveraged in mass-exploit campaigns targeting thousands of websites simultaneously [1].
Impact
An attacker successfully exploiting this vulnerability could perform unauthorized actions that should be restricted to higher-privileged users. Depending on the misconfigured functions, this might include modifying plugin settings, accessing sensitive data, or performing administrative operations. The CVSS v3 base score is 5.4 (Medium), reflecting the potential for significant site compromise [1].
Mitigation
The vendor has addressed this vulnerability in a subsequent release; users are strongly advised to update to the latest version of ListingPro. If immediate updating is not possible, temporary workarounds such as disabling the plugin or applying a web application firewall rule can help reduce risk [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=2.9.8
- Range: <= 2.9.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.