← back

CVE-2026-57355

MEDIUM · 6.5 EPSS 0.3%
hype PURE HYPE · 8 hack

Automated spam posts, mismatched CVSS, no PoC, no real engagement.

What: Broken access control in Classified Listing WordPress plugin versions ≤5.4.2 allowing subscribers to access restricted content (CVSS 6.5 medium).

Why it matters: Not KEV-listed; EPSS near zero (0.22%); no PoC or in-the-wild exploitation confirmed. Social posts are identical boilerplate repeats mentioning a mismatched CVSS (4.3 vs actual 6.5), suggesting automated spam rather than genuine researcher signal.

Where it's seen: Eight near-duplicate Bluesky posts with generic hashtags and no substantive analysis, technical detail, or exploit code. No vendor advisory or defender triage activity observed.

RISK: LOW — Medium CVSS but low EPSS, no KEV listing, zero exploitation signal.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 7/23/2026, 11:23:08 PM

Description

Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.

CVSS 3.1 breakdown

Exploitability 2.8 · Impact 3.6
vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack vector
Network
Complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Weaknesses