CVE-2026-57355
MEDIUM · 6.5 EPSS 0.3%Automated spam posts, mismatched CVSS, no PoC, no real engagement.
What: Broken access control in Classified Listing WordPress plugin versions ≤5.4.2 allowing subscribers to access restricted content (CVSS 6.5 medium).
Why it matters: Not KEV-listed; EPSS near zero (0.22%); no PoC or in-the-wild exploitation confirmed. Social posts are identical boilerplate repeats mentioning a mismatched CVSS (4.3 vs actual 6.5), suggesting automated spam rather than genuine researcher signal.
Where it's seen: Eight near-duplicate Bluesky posts with generic hashtags and no substantive analysis, technical detail, or exploit code. No vendor advisory or defender triage activity observed.
RISK: LOW — Medium CVSS but low EPSS, no KEV listing, zero exploitation signal.
Description
Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N- Attack vector
- Network
- Complexity
- Low
- Privileges required
- Low
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- None
- Integrity
- High
- Availability
- None