CVE-2025-63049: WordPress ListingPro Lead Form plugin <= 1.0.7 - Broken Access Control vulnerability
Missing Authorization vulnerability in CridioStudio ListingPro Lead Form listingpro-lead-form allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ListingPro Lead Form: from n/a through <= 1.0.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63049?
CVE-2025-63049 is categorized as a medium severity vulnerability due to its potential impact on unauthorized access.
How do I fix CVE-2025-63049?
To fix CVE-2025-63049, upgrade the ListingPro Lead Form plugin to a version higher than 1.0.2.
What software is affected by CVE-2025-63049?
CVE-2025-63049 affects the ListingPro Lead Form plugin for WordPress versions from n/a up to and including 1.0.2.
What type of vulnerability is CVE-2025-63049?
CVE-2025-63049 is a Missing Authorization vulnerability that allows access to functionality not properly constrained by Access Control Lists (ACLs).
Can CVE-2025-63049 lead to data exposure?
Yes, CVE-2025-63049 can potentially lead to unauthorized access and data exposure due to inadequate access controls.