CVE-2025-2253: IMITHEMES Listing <= 3.3 - Unauthenticated Privilege Escalation via Unverified Password Reset
The IMITHEMES Listing plugin is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3. This is due to the plugin not properly validating a verification code value prior to updating their password through the imicresetpasswordinit() function. This makes it possible for unauthenticated attackers to change any user's passwords, including administrators if the users email is known.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2253?
CVE-2025-2253 has a high severity rating due to its potential for privilege escalation via account takeover.
How do I fix CVE-2025-2253?
To fix CVE-2025-2253, update the IMITHEMES Listing plugin to version 3.4 or later.
What versions of the IMITHEMES Listing plugin are affected by CVE-2025-2253?
All versions of the IMITHEMES Listing plugin up to and including 3.3 are affected by CVE-2025-2253.
What is the cause of the vulnerability in CVE-2025-2253?
The vulnerability in CVE-2025-2253 is caused by improper validation of a verification code value during password updates.
Can CVE-2025-2253 lead to unauthorized access?
Yes, CVE-2025-2253 can lead to unauthorized access through the exploitation of privilege escalation.