Executive brief
The Classified Listing plugin for WordPress, which is used to manage business directories and classified advertisements, contains a security flaw that allows unauthorized users to modify order notes. An attacker with a basic user account can add arbitrary notes to any order and trigger automated notification or moderation emails to listing owners. This could be used to harass users or disrupt the normal administrative workflow of the directory.
Technical details
The Classified Listing plugin for WordPress is vulnerable to a missing authorization check (CWE-862) in versions up to 5.3.10. The vulnerability exists because the plugin does not properly verify user permissions before allowing actions related to order notes and listing notifications. An authenticated attacker with subscriber-level privileges or higher can exploit this by sending crafted requests to the server, enabling them to append arbitrary notes to any order. This action also triggers the plugin's automated email system, sending unsolicited moderation or notification emails to listing owners without the required administrative authorization. A patch appears to be available in version 5.3.11 based on the provided changeset references.
Affected products
- RadiusTheme Classified Listing – AI-Powered Classified ads & Business Directory Plugin Up to, and including, 5.3.10
Timeline
- 2026-05-15: disclosed: CVE published to NVD dataset
- 2026-05-15: advisory: Wordfence published vulnerability details
References
- https://plugins.trac.wordpress.org/browser/classified-listing/tags/5.3.10/app/Controllers/Admin/ScriptLoader.php
- https://plugins.trac.wordpress.org/browser/classified-listing/tags/5.3.10/app/Controllers/Ajax/ListingAdminAjax.php
- https://plugins.trac.wordpress.org/browser/classified-listing/tags/5.3.10/app/Controllers/Hooks/Comments.php
- https://plugins.trac.wordpress.org/browser/classified-listing/tags/5.3.10/app/Controllers/Hooks/Comments.php
- https://plugins.trac.wordpress.org/browser/classified-listing/tags/5.3.7/app/Controllers/Admin/ScriptLoader.php
- https://plugins.trac.wordpress.org/browser/classified-listing/tags/5.3.7/app/Controllers/Ajax/ListingAdminAjax.php
- https://plugins.trac.wordpress.org/browser/classified-listing/tags/5.3.7/app/Controllers/Hooks/Comments.php