PT-2025-32096 · WordPress · Reveal Listing

Alyudin Nafiie

·

Published

2025-08-06

·

Updated

2025-08-11

·

CVE-2025-6994

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Reveal Listing plugin for WordPress versions up to and including 3.3
Description The Reveal Listing plugin for WordPress allows users registering new accounts to set their own role via the listing user role field. This enables unauthenticated attackers to gain elevated privileges, potentially achieving site takeover, by creating an account with administrator privileges.
Recommendations Update to a version of the Reveal Listing plugin for WordPress later than 3.3.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-6994

Affected Products

Reveal Listing