Executive brief
Classified Listing is a WordPress plugin for creating and managing classified ad listings. A broken access control vulnerability allows subscribers to access pages and perform actions they are not authorized for, such as viewing other users' data or private listings. An attacker with a basic subscriber account can escalate their privileges to view or modify sensitive information, compromising site data integrity and user privacy.
Technical details
The vulnerability is classified as broken access control (CWE-276/639), affecting Classified Listing versions through 6.1.3. A subscriber-level user can bypass access control lists (ACLs) to access functionality and pages that should be restricted to higher-privilege accounts. The attack requires authentication as a subscriber but no additional preconditions. An attacker can view other users' private data, listings, or perform administrative actions. The issue is patched in version 6.1.5.
Affected products
- Mamunur Rashid Classified Listing through 6.1.3
Timeline
- 2026-07-22: disclosed: Reported to Patchstack
- 2026-09-02: advisory: Published by Patchstack and NVD
- 2026-09-02: patched: Patched in version 6.1.5