Executive brief
The Classified Listing plugin for WordPress, which allows users to create and manage classified ads, contains a security flaw that fails to properly restrict access to certain functions. This allows logged-in users with low-level 'Subscriber' permissions to perform actions or access data that should be reserved for administrators. Such an exploit could lead to unauthorized changes to site content or the exposure of sensitive information.
Technical details
The Classified Listing plugin for WordPress (versions up to and including 5.3.9) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). An attacker authenticated with a low-privilege account, such as a Subscriber, can exploit this flaw to perform actions that should be restricted to higher-privileged users. The vulnerability is reachable over the network without user interaction. The issue is resolved in version 5.3.10, which implements the necessary authorization checks.
Affected products
- Mamunur Rashid Classified Listing <= 5.3.9
Timeline
- 2026-03-10: other: Reported by Jakub Herman
- 2026-04-29: advisory: Initial disclosure by Patchstack
- 2026-04-29: patched: Patch released in version 5.3.10
- 2026-06-15: disclosed: NVD publication date