Unauthenticated Access Control Flaw in Classified Listing Plugin by WordPress
CVE-2026-42640
6.5MEDIUM
What is CVE-2026-42640?
The Classified Listing plugin for WordPress, specifically versions up to 5.3.8, has a vulnerability that allows unauthenticated users to exploit broken access control mechanisms. This security flaw can enable unauthorized access to sensitive areas of the application, potentially leading to data exposure or manipulation. It is critical for users of this plugin to update to the latest version to mitigate the associated risks.
Affected Version(s)
Classified Listing <= 5.3.8