Junglewise Threat Intelligence

CVE-2026-49063: Listdom WordPress plugin unauthenticated privilege escalation

CVE-2026-49063 · Severity: high · CVSS 7.3 · Published 2026-06-15

Executive brief

Listdom, a WordPress plugin used for creating directory and listing websites, contains a security flaw that allows unauthorized users to gain elevated administrative privileges. An attacker could exploit this to take full control of the website, potentially leading to data theft, site defacement, or complete service disruption. This vulnerability is particularly serious because it does not require the attacker to have an existing account on the site.

Technical details

The Listdom plugin for WordPress (versions 5.5.0 and below) is vulnerable to unauthenticated privilege escalation due to incorrect privilege assignment (CWE-266). The vulnerability allows a remote, unauthenticated attacker to escalate their privileges, potentially gaining full administrative control over the affected WordPress site. The flaw is categorized under OWASP Top 10 A7: Identification and Authentication Failures. A patch is available in version 5.6.0, which addresses the root cause of the improper permission checks.

Affected products

  • Listdom Listdom <= 5.5.0

Timeline

  • 2026-05-15: other: Reported by researcher dodoh4t
  • 2026-06-08: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date
  • 2026-06-08: patched: Version 5.6.0 released to address the vulnerability

References