← WordPress Vulnerabilities
WordPress security by component

Classified Listing

Classified Listing creates classified advertisements with listings, categories, search, user submissions, and listing management features in WordPress.

Classified Listing (classified-listing) is a WordPress plugin with 27 published CVE records in this archive. The latest tracked vulnerability was published Aug 03, 2026; the highest published CVSS base score is 8.8.

Plugin slug: classified-listing

CVE-2026-16276: Classified Listing exposes store revenue totals to Contributors

Classified Listing before 5.4.4 omits a capability check from an AJAX action that returns aggregated daily store-revenue totals. Any Contributor-or-higher user can call the action and read figures intended for Administrators and report managers. The CNA record does not disclose the AJAX action, date parameters, callback or response fields.

PublishedAug 03, 2026
Known safe version5.4.4
Published vulnerabilities for classified-listing
Safe version
Aug 03, 2026 CVE-2026-16276
Classified Listing exposes store revenue totals to Contributors
Classified Listing before 5.4.4 omits a capability check from an AJAX action that returns aggregated daily store-revenue totals. Any Contributor-or-higher user can call the action and read figures intended for Administrators and report managers. The CNA record does not disclose the AJAX action, date parameters, callback or response fields.
5.4.4
CVE2.7
NVDPending
Aug 03, 2026 CVE-2026-16274
Classified Listing lets Contributors read private content
Classified Listing before 5.4.4 exposes an AJAX action that returns post content without checking capability or ownership. A Contributor-or-higher user can supply an arbitrary post identifier and read posts, pages and custom post types belonging to other users, including draft, pending and private content. The CNA record does not disclose the action, identifier parameter or callback.
5.4.4
CVE2.7
NVDPending
Jul 21, 2026 CVE-2026-14183
Classified Listing: A security weakness
Classified Listing is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 5.3.9. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
5.3.9
CVE4.3
NVDPending
Jul 02, 2026 CVE-2026-57355
Classified Listing: Broken access control
Classified Listing is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 5.4.2. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
5.4.3
CVE6.5
NVDPending
Jul 02, 2026 CVE-2026-57344
Classified Listing: Cross-site scripting
Classified Listing is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 5.4.2. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
5.4.3
CVE7.1
NVDPending
Jun 19, 2026 CVE-2026-10779
Classified Listing – AI-Powered Classified ads & Business Directory: A security weakness
Classified Listing – AI-Powered Classified ads & Business Directory is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.4.2. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVDPending
Jun 15, 2026 CVE-2026-42658
Classified Listing: Cross-site scripting
Classified Listing is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 5.3.8. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
5.3.9
CVE7.1
NVDPending
Jun 15, 2026 CVE-2026-42651
Classified Listing: Broken access control
Classified Listing is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 5.3.9. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
5.3.10
CVE6.3
NVDPending
Jun 15, 2026 CVE-2026-42640
Classified Listing: Broken access control
Classified Listing is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 5.3.8. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
5.3.9
CVE6.5
NVDPending
Jun 01, 2026 CVE-2026-42679
Classified Listing: Filesystem traversal
Classified Listing is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is n/a through 5.3.8. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
5.3.9
CVE6.5
NVDPending
May 15, 2026 CVE-2026-7563
Classified Listing – AI-Powered Classified ads & Business Directory Plugin: A security weakness
Classified Listing – AI-Powered Classified ads & Business Directory Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.3.10. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVDPending
Mar 05, 2026 CVE-2026-23546
Classified Listing: A security weakness
Classified Listing is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending
Nov 17, 2025 CVE-2025-7711
The Classified Listing – Classified ads & Business Directory Plugin: A security weakness
The Classified Listing – Classified ads & Business Directory Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.4
NVDPending
Sep 03, 2025 CVE-2025-58601
Classified Listing: A security weakness
Classified Listing is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVDPending
Aug 14, 2025 CVE-2025-54698
Classified Listing: Cross-site scripting
Classified Listing is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.4
NVDPending
Jun 20, 2025 CVE-2025-52715
Classified Listing: Filesystem traversal
Classified Listing is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.5
NVDPending
Apr 17, 2025 CVE-2025-24745
Classified Listing: Cross-site scripting
Classified Listing is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.1
NVDPending
Feb 25, 2025 CVE-2025-1063
Classified Listing – Classified ads & Business Directory Plugin: Sensitive information exposure
Classified Listing – Classified ads & Business Directory Plugin is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.3
NVDPending
Nov 19, 2024 CVE-2024-11194
Classified Listing – Classified ads & Business Directory Plugin: Privilege escalation or authentication bypass
Classified Listing – Classified ads & Business Directory Plugin is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated subscriber account. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.8
NVDPending
Nov 16, 2024 CVE-2024-52386
Classified Listing: Filesystem traversal
Classified Listing is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.3
NVDPending
Sep 13, 2024 CVE-2024-7888
Classified Listing – Classified ads & Business Directory Plugin: A security weakness
Classified Listing – Classified ads & Business Directory Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.3
NVD4.3
Apr 25, 2024 CVE-2024-3893
Classified Listing – Classified ads & Business Directory Plugin: A security weakness
Classified Listing – Classified ads & Business Directory Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVD4.3
Apr 09, 2024 CVE-2024-1352
Classified Listing – Classified ads & Business Directory Plugin: A security weakness
Classified Listing – Classified ads & Business Directory Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVD5.3
Apr 09, 2024 CVE-2024-1315
Classified Listing – Classified ads & Business Directory Plugin: Cross-site request forgery
Classified Listing – Classified ads & Business Directory Plugin is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.8
NVDPending
Jul 18, 2023 CVE-2023-37387
Classified Listing: Cross-site request forgery
Classified Listing is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.4
NVD8.8
Sep 16, 2022 CVE-2022-2655
Classified Listing Pro: Cross-site scripting
Classified Listing Pro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVEPending
NVD6.1
Sep 16, 2022 CVE-2022-2654
Classima: Cross-site scripting
Classima is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.1
NVD6.1