Junglewise Threat Intelligence

CVE-2026-57344: RadiusTheme Classified Listing unauthenticated XSS

CVE-2026-57344 · Severity: high · CVSS 7.1 · Published 2026-07-02

Technologies: RadiusTheme Classified Listing. Vendors: RadiusTheme.

Executive brief

The Classified Listing plugin for WordPress, which allows users to create and manage classified ads, contains a security vulnerability that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could potentially hijack user sessions, redirect visitors to malicious websites, or deface the site. This issue affects all versions up to and including 5.4.2 and can be resolved by updating to version 5.4.3.

Technical details

The Classified Listing plugin for WordPress (versions <= 5.4.2) is vulnerable to Unauthenticated Cross-Site Scripting (XSS) due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted page. Because the vulnerability is 'unauthenticated' and has a 'changed' scope in the CVSS vector, it allows for the execution of arbitrary JavaScript in the victim's browser session, which can lead to session hijacking or unauthorized actions on behalf of the user. The issue is fixed in version 5.4.3.

Affected products

  • RadiusTheme Classified Listing <= 5.4.2

Timeline

  • 2026-05-03: disclosed: Reported by researcher daroo
  • 2026-06-29: advisory: Patchstack published advisory
  • 2026-07-02: advisory: NVD published CVE-2026-57344
  • 2026-06-29: patched: Version 5.4.3 released to address the vulnerability

References

Related threats