AJAX Vulnerability in Classified Listing Plugin for WordPress by Classified Listing
CVE-2026-16274
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 3 August 2026
Badges
What is CVE-2026-16274?
The Classified Listing plugin for WordPress prior to version 5.4.4 is susceptible to an improper access control vulnerability. This flaw arises from the lack of capability or ownership checks on an AJAX action that retrieves post content. As a result, users with contributor-level access and higher can exploit this vulnerability to access the content of any post, page, or custom post type on the site, including drafts, pending posts, and private posts owned by other users, irrespective of ownership. Such a vulnerability can lead to severe data exposure, thus highlighting the importance of applying the latest security updates.
Affected Version(s)
Classified Listing 0 < 5.4.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.