VYPR
Medium severity5.3NVD Advisory· Published Dec 9, 2025· Updated Apr 15, 2026

CVE-2025-63047

CVE-2025-63047

Description

Missing Authorization vulnerability in CridioStudio ListingPro listingpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingPro: from n/a through <= 2.9.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Vulnerability

Overview [1] The ListingPro theme for WordPress, developed by CridioStudio suffers from a missing authorization vulnerability affecting versions up to and including 2.9.9. This issue stems from incorrectly configured levels of access control security, which can be exploited by attackers to bypass intended restrictions. The vulnerability is classified as a broken access control problem, meaning that functions within the theme lack proper authorization checks, such as nonce tokens or capability verification. [1]

Exploitation and

Attack Surface [1] This vulnerability is particularly dangerous because it can be exploited without authentication, allowing unprivileged users to execute actions that should require higher privileges. Attackers can leverage this flaw in mass-exploit campaigns, targeting thousands of websites regardless of their traffic or popularity. The attack surface is broad, as any site running the vulnerable versionPro theme is potentially at risk. [1]

Impact and

Mitigation Successful exploitation could allow an attacker to perform unauthorized actions, potentially leading to data exposure, site defacement, or other malicious outcomes. The vendor has not released a patch, and users are strongly advised to update the theme immediately if a patched version becomes available. As a temporary measure, users should contact their hosting provider or a web developer for assistance in mitigating the risk. The vulnerability has a CVSS v3 score of 5.3 (Medium), indicating a moderate severity level. [1]

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.