Unauthorized Access in WPAdverts Plugin for WordPress
CVE-2026-11801

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 August 2026

What is CVE-2026-11801?

The WPAdverts – Classifieds Plugin for WordPress is susceptible to an authorization bypass vulnerability in all versions up to and including 2.3.2. This flaw arises from inadequate verification of a user's authorization to execute specific actions. Consequently, this vulnerability empowers unauthenticated attackers to access sensitive internal site configuration data through the classifieds-types REST endpoint. Information potentially exposed includes registered post types, taxonomy labels, form scheme metadata, contact options, and custom field meta keys, increasing the risk of site compromise.

Affected Version(s)

WPAdverts – Classifieds Plugin 0 <= 2.3.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Deva Parekh
.