The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.3. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'listing_user_role' field. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role.
Metrics
Affected Vendors & Products
References
History
Wed, 06 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 06 Aug 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Smartdatasoft
Smartdatasoft reveal Listing Wordpress Wordpress wordpress |
|
Vendors & Products |
Smartdatasoft
Smartdatasoft reveal Listing Wordpress Wordpress wordpress |
Wed, 06 Aug 2025 04:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.3. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'listing_user_role' field. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role. | |
Title | Reveal Listing <= 3.3 - Unauthenticated Privilege Escalation | |
Weaknesses | CWE-269 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-08-06T03:41:01.031Z
Updated: 2025-08-06T19:29:22.342Z
Reserved: 2025-07-01T21:35:42.219Z
Link: CVE-2025-6994

Updated: 2025-08-06T19:29:18.550Z

Status : Awaiting Analysis
Published: 2025-08-06T04:16:20.197
Modified: 2025-08-06T20:23:37.600
Link: CVE-2025-6994

No data.