HivePress Claim Listings

HivePress Claim Listings has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10. 2025 was the busiest year with 2 disclosures.

The most common weakness is Missing Authorization, behind 2 of the records (100%).

1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.

All of these findings were reported by Bao - BlueRock. HivePress Claim Listings is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage50%
Open

1

Fixed

1

Get automatic notifications for all HivePress Claim Listings vulnerabilities before they are exploited.

Most severe open issueCVSS 4.3CVE-2025-60122

HivePress Claim Listings <= 1.1.3 - Missing Authorization

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv1.1.4

HivePress Claim Listings

HivePress

Author

HivePress

5.0(1)
100/100
Last Updated
2026-08-24 (20d ago)
Active Installs
3,000+
Downloads
50,325
Requires WP
5.0+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2019-10-25 (7y ago)

HivePress Claim Listings is an extension for HivePress plugin. It allows you to charge users for claiming listings. Demo | Docs | Support

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C