Unauthenticated XSS Vulnerability in Classified Listing WordPress Plugin
CVE-2026-96351

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
30 September 2026

What is CVE-2026-96351?

A security flaw has been identified in the Classified Listing plugin for WordPress, specifically affecting versions up to 6.1.3. This vulnerability allows unauthenticated users to exploit Cross Site Scripting (XSS), potentially leading to malicious actions within user sessions or data theft. It is crucial for users and site administrators to apply necessary updates and take protective measures to secure their WordPress instances against this threat.

Affected Version(s)

Classified Listing <= 6.1.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manop55555 | Patchstack Bug Bounty Program
.