CVE-2025-68072

WordPress Easy Property Listings plugin <= 3.5.17 - Broken Access Control vulnerability

Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Property Listings: from n/a through <= 3.5.17.


We have discovered 1,308 live websites that are affected by CVE-2025-68072.

Run a Free Instant Scan




Affected Software

Product  Easy Property Listings
Category Wordpress Plugins
Vulnerable Domains1,308 live websites (100% of Easy Property Listings install base)
Vulnerable Versions
  • from 0 through 3.5.17
Vulnerable Versions Count49 versions ( 100% of all versions)



Details

  • Published - Jan 22, 2026
  • Updated - Jan 28, 2026

Credits

  • daroo | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2025-68072
United States550 websites



Australia314 websites
GB63 websites
Germany51 websites
Italy40 websites
Canada35 websites
France25 websites
Netherlands22 websites
Spain18 websites
South Africa18 websites

Website Distribution by TLD

Number of websites using CVE-2025-68072
.com616 websites
.com.au340 websites
.co.uk43 websites
.net25 websites
.org25 websites
.it24 websites
.de19 websites
.ca17 websites
.nl15 websites
.fr10 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-68072

Top websites that are affected by CVE-2025-68072. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********************.com United States***,***
*************.**.nz United States***,***
**************.com United States***,***
**************.de Germany***,***
***********.de Germany*,***,***
***********************.***.au Australia*,***,***
*************.***.au Australia*,***,***
*************.**.za South Africa*,***,***
**********.it Italy*,***,***
***********.it Italy*,***,***
See full domain list

FAQ

A total of 1,308 websites have been identified as vulnerable to CVE-2025-68072, based on global website indexing conducted by WebTechSurvey.
The Easy Property Listings is affected by the CVE-2025-68072 vulnerability.
Easy Property Listings versions up to and including 3.5.17 are vulnerable to CVE-2025-68072.