Executive brief
Advanced Classifieds & Directory Pro is a WordPress plugin that manages classified listings and directory features. The plugin exposes sensitive custom field data (phone numbers, addresses, pricing) from draft, pending, and private listings to unauthenticated attackers through an unprotected AJAX endpoint, allowing unauthorized disclosure of information that should not be publicly visible.
Technical details
The vulnerability is an authorization bypass in the AJAX action `acadp_public_custom_fields_listings`, where the callback function `ajax_callback_custom_fields()` retrieves post metadata without verifying post ownership, post status, or user capabilities. Although the endpoint includes a CSRF nonce check via `check_ajax_referer()`, the nonce is publicly available via `wp_localize_script()`, providing no meaningful authorization control. An unauthenticated attacker can supply an arbitrary `post_id` parameter and retrieve custom field values for any listing, including those in non-public statuses. The vulnerability is network-accessible, requires only the plugin to be active with at least one custom field configured, and no user interaction or authentication. Versions prior to 3.4.3 are affected; patched version 3.4.3 is available.
Affected products
- Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro before 3.4.3
Timeline
- 2026-08-07: disclosed
- 2026-08-10: patched: Version 3.4.3 released