CVE 9.8 CRITICAL

Reveal Listing <= 3.3 - Unauthenticated Privilege Escalation_CVE-2025-6994

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.3. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'listing_user_role' field. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role.

Basic Information

ID CVE-2025-6994
Source Wordfence
Published Aug 6, 2025 at 03:41
Modified Aug 6, 2025 at 19:29

Affected Product

Vendor SmartDataSoft
Product Reveal Listing
Version *
Affected Versions SmartDataSoft Reveal Listing *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.