Junglewise Threat Intelligence

CVE-2026-27391: Stylemix uListing broken access control in WordPress plugin

CVE-2026-27391 · Severity: medium · CVSS 5.4 · Published 2026-07-23

Vendors: StylemixThemes.

Executive brief

uListing, a WordPress plugin used for creating business directories and listing sites, contains a security flaw that allows users with basic 'Subscriber' accounts to perform unauthorized actions. An attacker with a low-level account could potentially modify site data or disrupt operations by bypassing intended access restrictions. This could lead to unauthorized changes to listings or minor service disruptions on the affected website.

Technical details

A broken access control vulnerability (CWE-862: Missing Authorization) exists in the Stylemix uListing plugin for WordPress in versions up to 2.2.0. The flaw is rooted in insufficient authorization checks, which allows an authenticated attacker with Subscriber-level privileges to execute functions or actions that should be restricted to higher-privileged users. The attack is network-reachable and requires low privileges but no user interaction. Successful exploitation could allow an attacker to modify data or impact the availability of certain plugin features. As of the advisory date, no official patch has been confirmed.

Affected products

  • StylemixThemes uListing <= 2.2.0

Timeline

  • 2025-11-16: other: Vulnerability reported by researcher daroo
  • 2026-07-22: advisory: Patchstack published advisory
  • 2026-07-23: disclosed: CVE published to NVD dataset

References

Related threats