Executive brief
The Classified Listing plugin for WordPress, which allows users to create and manage classified ads, contains a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could steal session information, redirect users to malicious sites, or deface the website. This vulnerability can be exploited by anyone on the internet without needing an account on the affected site.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the Classified Listing plugin for WordPress due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Exploitation requires a victim (typically a site administrator) to perform an action, such as clicking a malicious link or visiting a crafted page (User Interaction required). Successful exploitation can lead to session hijacking, unauthorized actions in the context of the victim's browser, or site defacement. The vulnerability is addressed in version 5.3.9.
Affected products
- Mamunur Rashid Classified Listing <= 5.3.8
Timeline
- 2026-03-23: disclosed: Reported by endy via Patchstack
- 2026-04-29: advisory: Initial advisory published by Patchstack
- 2026-06-15: advisory: NVD publication date
- 2026-05-01: patched: Fixed in version 5.3.9