Missing Authorization Vulnerability in Classified Listing Plugin for WordPress
CVE-2026-10779

4.3MEDIUM

What is CVE-2026-10779?

The Classified Listing plugin for WordPress is vulnerable due to a lack of capability and ownership checks in its AJAX handler. This vulnerability allows authenticated users, such as those with Subscriber-level access, to alter the featured images of listings that they do not own simply by supplying a valid listing ID and attachment ID. As the nonce used for validation is accessible to any logged-in user on the frontend, the risk of exploitation is significant, enabling unauthorized changes to listings and potential abuse of the platform. Users should update to the latest version to mitigate this issue.

Affected Version(s)

Classified Listing – AI-Powered Classified ads & Business Directory 0 <= 5.4.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ben Tamam
.