Junglewise Threat Intelligence

CVE-2026-42679: Mamunur Rashid Classified Listing path traversal in arbitrary file download

CVE-2026-42679 · Severity: medium · CVSS 6.5 · Published 2026-06-01

Technologies: Mamunur Rashid Classified Listing. Vendors: RadiusTheme.

Executive brief

The Classified Listing plugin for WordPress, which allows users to create and manage classified ads, contains a security flaw that could allow unauthorized file access. An attacker with a basic user account can exploit this to download sensitive files from the web server, such as configuration files containing database credentials or site backups. This could lead to a full compromise of the website and its data.

Technical details

A path traversal vulnerability (CWE-22) exists in the Mamunur Rashid Classified Listing plugin for WordPress up to version 5.3.8. The flaw allows an authenticated attacker with 'Subscriber' level privileges to bypass directory restrictions and download arbitrary files from the server. This is achieved by providing manipulated file paths to a vulnerable component within the plugin. Successful exploitation can lead to the disclosure of sensitive information, including wp-config.php or other system files. The issue is resolved in version 5.3.9.

Affected products

  • Mamunur Rashid Classified Listing <= 5.3.8

Timeline

  • 2026-04-17: other: Reported by researcher thevietronin
  • 2026-05-17: advisory: Patchstack advisory published
  • 2026-06-01: disclosed: CVE published to NVD
  • 2026-05-17: patched: Version 5.3.9 released to address the vulnerability

References

Related threats