CVE-2025-58710
8.6e-plugins · Hotel Listing
The Hotel Listing plugin for WordPress contains an incorrect privilege assignment vulnerability that allows authenticated users to escalate their privileges.
Executive summary
A privilege escalation vulnerability in the e-plugins Hotel Listing plugin allows authenticated users to gain unauthorized access and elevate their permissions, posing a high risk to system integrity.
Vulnerability
This vulnerability involves an incorrect privilege assignment (CWE-266) within the plugin. An authenticated user can exploit this flaw to escalate privileges, effectively gaining higher levels of access than intended by the site administrator.
Business impact
Successful exploitation of this vulnerability allows a malicious actor to escalate their privileges to an administrative or high-level account. With a CVSS score of 8.6, this flaw represents a high risk, as it could lead to full site compromise, unauthorized data access, and the potential for complete control over the WordPress environment.
Remediation
Immediate Action: Given that a specific patched version is not explicitly identified in the provided data, administrators should immediately disable or remove the Hotel Listing plugin until a secure update is released by the vendor.
Proactive Monitoring: Monitor WordPress user logs and access control lists for any suspicious changes to user roles or unauthorized administrative actions performed by standard accounts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to monitor for and block requests that attempt to manipulate privilege levels or exploit known plugin-specific endpoints.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
The severity of this privilege escalation vulnerability necessitates immediate action to prevent unauthorized administrative access. Security teams should prioritize the removal of the vulnerable plugin and audit current user roles to ensure that no unauthorized privilege changes have already occurred within the application environment.
Sources
Originally found and disclosed by João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program, per the CVE Program record.