Access Control Flaw in Classified Listing by Mamunur Rashid
CVE-2026-84217

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 September 2026

What is CVE-2026-84217?

The Classified Listing plugin developed by Mamunur Rashid is exposed to a Missing Authorization vulnerability, which allows attackers to access functionalities that are not properly constrained by Access Control Lists (ACLs). This issue affects versions up to and including 6.1.1, potentially compromising the security of sensitive data and user integrity on WordPress sites utilizing this plugin.

Affected Version(s)

Classified Listing <= 6.1.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Bilal (bilalmajid_1) | Patchstack Bug Bounty Program
.