Access Control Flaw in Classified Listing by Mamunur Rashid
CVE-2026-84217
5.4MEDIUM
What is CVE-2026-84217?
The Classified Listing plugin developed by Mamunur Rashid is exposed to a Missing Authorization vulnerability, which allows attackers to access functionalities that are not properly constrained by Access Control Lists (ACLs). This issue affects versions up to and including 6.1.1, potentially compromising the security of sensitive data and user integrity on WordPress sites utilizing this plugin.
Affected Version(s)
Classified Listing <= 6.1.1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Muhammad Bilal (bilalmajid_1) | Patchstack Bug Bounty Program