Junglewise Threat Intelligence

CVE-2026-42640: Classified Listing broken access control in WordPress plugin

CVE-2026-42640 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Technologies: Mamunur Rashid Classified Listing.

Executive brief

The Classified Listing plugin for WordPress, which allows users to create and manage classified ads, contains a security flaw that allows unauthorized individuals to perform actions they should not have access to. An attacker could potentially modify or access data without needing to log in. This could lead to unauthorized changes to site listings or exposure of internal information, impacting the integrity of the classifieds platform.

Technical details

The Classified Listing plugin for WordPress (versions <= 5.3.8) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). This flaw allows an unauthenticated remote attacker to execute functions or access data that should be restricted to higher-privileged users. The vulnerability stems from a failure to validate user permissions or implement proper nonce checks on specific plugin endpoints. Attackers can exploit this over the network without any user interaction. The issue is resolved in version 5.3.9.

Affected products

  • Mamunur Rashid Classified Listing <= 5.3.8

Timeline

  • 2026-01-12: disclosed: Reported by Cruzer to Patchstack
  • 2026-04-29: advisory: Patchstack published the vulnerability details
  • 2026-06-15: advisory: NVD published the CVE record
  • 2026-04-29: patched: Version 5.3.9 released to address the issue

References