CVE-2025-60123
Description
Missing Authorization vulnerability in HivePress HivePress Claim Listings hivepress-claim-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HivePress Claim Listings: from n/a through <= 1.1.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in HivePress Claim Listings plugin ≤1.1.3 allows unauthenticated exploitation of incorrectly configured access controls.
Vulnerability
Overview The HivePress Claim Listings plugin for WordPress versions up to and including 1.1.3 suffers from a missing authorization vulnerability. This flaw stems from improperly configured access control security levels, allowing unauthenticated users to perform actions that should require higher privileges [1].
Exploitation
Conditions Attackers can exploit this vulnerability without authentication or prior knowledge, simply by sending crafted requests to the affected plugin endpoints. The issue is classified as a broken access control, meaning no nonce or capability checks are in place to verify the user's authorization for certain functions [1].
Impact
Successful exploitation can lead to unauthorized actions such as claiming listings or modifying plugin settings, potentially compromising the integrity of the website's listing management. While the CVSS score is 4.3 (medium), the vulnerability is considered low severity and unlikely to be exploited in mass campaigns, though it remains a risk for site owners [1].
Mitigation
The vulnerability is patched in version 1.1.4. Users are strongly advised to update immediately. If updating is not possible, administrators should implement additional access controls or consult their hosting provider for alternative mitigations. Patchstack users can enable auto-updates for vulnerable plugins [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<=1.1.3+ 1 more
- (no CPE)range: <=1.1.3
- (no CPE)range: <= 1.1.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.