SmartDataSoft Vulnerabilities and Affected Products
Vulnerabilities associated with Reveal Listing.
Products
Clear product- DriCub2 vulnerabilities
- Essential WP Real Estate2 vulnerabilities
- SmartBlog2 vulnerabilities
- Car Repair Services1 vulnerability
- Clasifico Listing1 vulnerability
- Electrician - Electrical Service WordPress1 vulnerability
- Pool Services1 vulnerability
- Resido - Real Estate WordPress Theme1 vulnerability
- Reveal Listing1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-6994CRITICAL | Reveal Listing <= 3.3 - Unauthenticated Privilege EscalationThe Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.3. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'listing_user_role' field. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role. CWE-269Aug 6, 2025 | CVSS9.8v3.1 | EPSS0.395% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |