Unauthorized Access in WPAdverts Plugin for WordPress
CVE-2026-11801
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 August 2026
What is CVE-2026-11801?
The WPAdverts β Classifieds Plugin for WordPress is susceptible to an authorization bypass vulnerability in all versions up to and including 2.3.2. This flaw arises from inadequate verification of a user's authorization to execute specific actions. Consequently, this vulnerability empowers unauthenticated attackers to access sensitive internal site configuration data through the classifieds-types REST endpoint. Information potentially exposed includes registered post types, taxonomy labels, form scheme metadata, contact options, and custom field meta keys, increasing the risk of site compromise.
Affected Version(s)
WPAdverts β Classifieds Plugin 0 <= 2.3.2