WordPress security by component
Classified Listing
Plugin description
Classified Listing creates classified advertisements with listings, categories, search, user submissions, and listing management features in WordPress.
Classified Listing (classified-listing) is a WordPress plugin with 29 published CVE records in this archive. The latest tracked vulnerability was published Sep 04, 2026; the highest published CVSS base score is 8.8.
Plugin slug:
classified-listingLatest vulnerability
CVE-2026-16281: Classified Listing subscribers can alter media on other users' listings
Classified Listing versions 5.3.0 through 6.1.0 do not verify that the caller owns or can edit a listing before its AI image-editing action deletes or attaches media. A Subscriber can permanently delete attachments from, or attach files to, another user's listing.
| Safe version |
|
||
|---|---|---|---|
| Sep 04, 2026 |
CVE-2026-16281
Classified Listing subscribers can alter media on other users' listings
Classified Listing versions 5.3.0 through 6.1.0 do not verify that the caller owns or can edit a listing before its AI image-editing action deletes or attaches media. A Subscriber can permanently delete attachments from, or attach files to, another user's listing.
|
6.1.1 |
CVE7.1
NVDPending
|
| Sep 02, 2026 |
CVE-2026-84217
Classified Listing users can invoke an unauthorized operation
Classified Listing through 6.1.1 does not enforce the required authorization on an affected operation. A low-privilege authenticated user can cross that access-control boundary, change protected state, and disrupt related functionality.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Aug 03, 2026 |
CVE-2026-16276
Classified Listing exposes store revenue totals to Contributors
Classified Listing before 5.4.4 omits a capability check from an AJAX action that returns aggregated daily store-revenue totals. Any Contributor-or-higher user can call the action and read figures intended for Administrators and report managers.
|
5.4.4 |
CVE2.7
NVDPending
|
| Aug 03, 2026 |
CVE-2026-16274
Classified Listing lets Contributors read private content
Classified Listing before 5.4.4 exposes an AJAX action that returns post content without checking capability or ownership. A Contributor-or-higher user can supply an arbitrary post identifier and read posts, pages and custom post types belonging to other users, including draft, pending and private content.
|
5.4.4 |
CVE2.7
NVDPending
|
| Jul 21, 2026 |
CVE-2026-14183
Classified Listing: A security weakness
Classified Listing is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 5.3.9.
|
5.3.9 |
CVE4.3
NVDPending
|
| Jul 02, 2026 |
CVE-2026-57355
Classified Listing: Broken access control
Classified Listing is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 5.4.2.
|
5.4.3 |
CVE6.5
NVDPending
|
| Jul 02, 2026 |
CVE-2026-57344
Classified Listing: Cross-site scripting
Classified Listing is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 5.4.2.
|
5.4.3 |
CVE7.1
NVDPending
|
| Jun 19, 2026 |
CVE-2026-10779
Classified Listing – AI-Powered Classified ads & Business Directory: A security weakness
Classified Listing – AI-Powered Classified ads & Business Directory is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.4.2.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-42658
Classified Listing: Cross-site scripting
Classified Listing is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 5.3.8.
|
5.3.9 |
CVE7.1
NVDPending
|
| Jun 15, 2026 |
CVE-2026-42651
Classified Listing: Broken access control
Classified Listing is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 5.3.9.
|
5.3.10 |
CVE6.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-42640
Classified Listing: Broken access control
Classified Listing is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 5.3.8.
|
5.3.9 |
CVE6.5
NVDPending
|
| Jun 01, 2026 |
CVE-2026-42679
Classified Listing: Filesystem traversal
Classified Listing is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is n/a through 5.3.8.
|
5.3.9 |
CVE6.5
NVDPending
|
| May 15, 2026 |
CVE-2026-7563
Classified Listing – AI-Powered Classified ads & Business Directory Plugin: A security weakness
Classified Listing – AI-Powered Classified ads & Business Directory Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.3.10.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Mar 05, 2026 |
CVE-2026-23546
Classified Listing: A security weakness
Classified Listing is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Nov 17, 2025 |
CVE-2025-7711
The Classified Listing – Classified ads & Business Directory Plugin: A security weakness
The Classified Listing – Classified ads & Business Directory Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Sep 03, 2025 |
CVE-2025-58601
Classified Listing: A security weakness
Classified Listing is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Aug 14, 2025 |
CVE-2025-54698
Classified Listing: Cross-site scripting
Classified Listing is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jun 20, 2025 |
CVE-2025-52715
Classified Listing: Filesystem traversal
Classified Listing is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Apr 17, 2025 |
CVE-2025-24745
Classified Listing: Cross-site scripting
Classified Listing is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Feb 25, 2025 |
CVE-2025-1063
Classified Listing – Classified ads & Business Directory Plugin: Sensitive information exposure
Classified Listing – Classified ads & Business Directory Plugin is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Nov 19, 2024 |
CVE-2024-11194
Classified Listing – Classified ads & Business Directory Plugin: Privilege escalation or authentication bypass
Classified Listing – Classified ads & Business Directory Plugin is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated subscriber account. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Nov 16, 2024 |
CVE-2024-52386
Classified Listing: Filesystem traversal
Classified Listing is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 13, 2024 |
CVE-2024-7888
Classified Listing – Classified ads & Business Directory Plugin: A security weakness
Classified Listing – Classified ads & Business Directory Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.3
NVD4.3
|
| Apr 25, 2024 |
CVE-2024-3893
Classified Listing – Classified ads & Business Directory Plugin: A security weakness
Classified Listing – Classified ads & Business Directory Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 09, 2024 |
CVE-2024-1352
Classified Listing – Classified ads & Business Directory Plugin: A security weakness
Classified Listing – Classified ads & Business Directory Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD5.3
|
| Apr 09, 2024 |
CVE-2024-1315
Classified Listing – Classified ads & Business Directory Plugin: Cross-site request forgery
Classified Listing – Classified ads & Business Directory Plugin is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Jul 18, 2023 |
CVE-2023-37387
Classified Listing: Cross-site request forgery
Classified Listing is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Sep 16, 2022 |
CVE-2022-2655
Classified Listing Pro: Cross-site scripting
Classified Listing Pro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Sep 16, 2022 |
CVE-2022-2654
Classima: Cross-site scripting
Classima is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|