CVE-2025-6994: Reveal Listing <= 3.3 - Unauthenticated Privilege Escalation
The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.3. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'listinguserrole' field. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6994?
CVE-2025-6994 has a severity rating that indicates a significant risk of privilege escalation affecting the Reveal Listing plugin for WordPress.
How do I fix CVE-2025-6994?
To fix CVE-2025-6994, update the Reveal Listing plugin to version 3.4 or later, which addresses the privilege escalation vulnerability.
Who is affected by CVE-2025-6994?
CVE-2025-6994 affects users of the Reveal Listing plugin by smartdatasoft for WordPress in versions 3.3 and earlier.
What type of vulnerability is CVE-2025-6994?
CVE-2025-6994 is a privilege escalation vulnerability that allows users to set their own roles when registering new accounts.
What versions of the Reveal Listing plugin are vulnerable to CVE-2025-6994?
Versions of the Reveal Listing plugin up to and including 3.3 are vulnerable to CVE-2025-6994.