Missing Authorization Vulnerability in Classified Listing Plugin for WordPress
CVE-2026-10779
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 June 2026
What is CVE-2026-10779?
The Classified Listing plugin for WordPress is vulnerable due to a lack of capability and ownership checks in its AJAX handler. This vulnerability allows authenticated users, such as those with Subscriber-level access, to alter the featured images of listings that they do not own simply by supplying a valid listing ID and attachment ID. As the nonce used for validation is accessible to any logged-in user on the frontend, the risk of exploitation is significant, enabling unauthorized changes to listings and potential abuse of the platform. Users should update to the latest version to mitigate this issue.
Affected Version(s)
Classified Listing β AI-Powered Classified ads & Business Directory 0 <= 5.4.2