Data Modification Vulnerability in Ultimate Classified Listings Plugin for WordPress
CVE-2025-0763
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 September 2025
What is CVE-2025-0763?
The Ultimate Classified Listings plugin for WordPress is susceptible to unauthorized data modification due to a lack of capability checks within the save_custom_fields function. This vulnerability allows authenticated users with Subscriber-level access and higher to alter custom fields within the plugin. All versions up to and including 1.6 are affected, highlighting the importance of implementing proper access controls to prevent potential security breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Ultimate Classified Listings * <= 1.6
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ivan Kuzymchak