WordPress security by component
Classified Listing
Plugin description
Classified Listing creates classified advertisements with listings, categories, search, user submissions, and listing management features in WordPress.
Classified Listing (classified-listing) is a WordPress plugin with 27 published CVE records in this archive. The latest tracked vulnerability was published Aug 03, 2026; the highest published CVSS base score is 8.8.
Plugin slug:
classified-listingLatest vulnerability
CVE-2026-16276: Classified Listing exposes store revenue totals to Contributors
Classified Listing before 5.4.4 omits a capability check from an AJAX action that returns aggregated daily store-revenue totals. Any Contributor-or-higher user can call the action and read figures intended for Administrators and report managers. The CNA record does not disclose the AJAX action, date parameters, callback or response fields.
| Safe version |
|
||
|---|---|---|---|
| Aug 03, 2026 |
CVE-2026-16276
Classified Listing exposes store revenue totals to Contributors
Classified Listing before 5.4.4 omits a capability check from an AJAX action that returns aggregated daily store-revenue totals. Any Contributor-or-higher user can call the action and read figures intended for Administrators and report managers. The CNA record does not disclose the AJAX action, date parameters, callback or response fields.
|
5.4.4 |
CVE2.7
NVDPending
|
| Aug 03, 2026 |
CVE-2026-16274
Classified Listing lets Contributors read private content
Classified Listing before 5.4.4 exposes an AJAX action that returns post content without checking capability or ownership. A Contributor-or-higher user can supply an arbitrary post identifier and read posts, pages and custom post types belonging to other users, including draft, pending and private content. The CNA record does not disclose the action, identifier parameter or callback.
|
5.4.4 |
CVE2.7
NVDPending
|
| Jul 21, 2026 |
CVE-2026-14183
Classified Listing: A security weakness
Classified Listing is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 5.3.9. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
5.3.9 |
CVE4.3
NVDPending
|
| Jul 02, 2026 |
CVE-2026-57355
Classified Listing: Broken access control
Classified Listing is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 5.4.2. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
5.4.3 |
CVE6.5
NVDPending
|
| Jul 02, 2026 |
CVE-2026-57344
Classified Listing: Cross-site scripting
Classified Listing is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 5.4.2. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
5.4.3 |
CVE7.1
NVDPending
|
| Jun 19, 2026 |
CVE-2026-10779
Classified Listing – AI-Powered Classified ads & Business Directory: A security weakness
Classified Listing – AI-Powered Classified ads & Business Directory is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.4.2. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-42658
Classified Listing: Cross-site scripting
Classified Listing is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 5.3.8. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
5.3.9 |
CVE7.1
NVDPending
|
| Jun 15, 2026 |
CVE-2026-42651
Classified Listing: Broken access control
Classified Listing is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 5.3.9. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
5.3.10 |
CVE6.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-42640
Classified Listing: Broken access control
Classified Listing is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 5.3.8. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
5.3.9 |
CVE6.5
NVDPending
|
| Jun 01, 2026 |
CVE-2026-42679
Classified Listing: Filesystem traversal
Classified Listing is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is n/a through 5.3.8. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
5.3.9 |
CVE6.5
NVDPending
|
| May 15, 2026 |
CVE-2026-7563
Classified Listing – AI-Powered Classified ads & Business Directory Plugin: A security weakness
Classified Listing – AI-Powered Classified ads & Business Directory Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.3.10. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Mar 05, 2026 |
CVE-2026-23546
Classified Listing: A security weakness
Classified Listing is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Nov 17, 2025 |
CVE-2025-7711
The Classified Listing – Classified ads & Business Directory Plugin: A security weakness
The Classified Listing – Classified ads & Business Directory Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Sep 03, 2025 |
CVE-2025-58601
Classified Listing: A security weakness
Classified Listing is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Aug 14, 2025 |
CVE-2025-54698
Classified Listing: Cross-site scripting
Classified Listing is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jun 20, 2025 |
CVE-2025-52715
Classified Listing: Filesystem traversal
Classified Listing is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Apr 17, 2025 |
CVE-2025-24745
Classified Listing: Cross-site scripting
Classified Listing is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Feb 25, 2025 |
CVE-2025-1063
Classified Listing – Classified ads & Business Directory Plugin: Sensitive information exposure
Classified Listing – Classified ads & Business Directory Plugin is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Nov 19, 2024 |
CVE-2024-11194
Classified Listing – Classified ads & Business Directory Plugin: Privilege escalation or authentication bypass
Classified Listing – Classified ads & Business Directory Plugin is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated subscriber account. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Nov 16, 2024 |
CVE-2024-52386
Classified Listing: Filesystem traversal
Classified Listing is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 13, 2024 |
CVE-2024-7888
Classified Listing – Classified ads & Business Directory Plugin: A security weakness
Classified Listing – Classified ads & Business Directory Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.3
NVD4.3
|
| Apr 25, 2024 |
CVE-2024-3893
Classified Listing – Classified ads & Business Directory Plugin: A security weakness
Classified Listing – Classified ads & Business Directory Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 09, 2024 |
CVE-2024-1352
Classified Listing – Classified ads & Business Directory Plugin: A security weakness
Classified Listing – Classified ads & Business Directory Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD5.3
|
| Apr 09, 2024 |
CVE-2024-1315
Classified Listing – Classified ads & Business Directory Plugin: Cross-site request forgery
Classified Listing – Classified ads & Business Directory Plugin is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Jul 18, 2023 |
CVE-2023-37387
Classified Listing: Cross-site request forgery
Classified Listing is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Sep 16, 2022 |
CVE-2022-2655
Classified Listing Pro: Cross-site scripting
Classified Listing Pro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Sep 16, 2022 |
CVE-2022-2654
Classima: Cross-site scripting
Classima is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.1
NVD6.1
|