Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 14 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Techlabpro1
Techlabpro1 classified Listing Plugin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Techlabpro1
Techlabpro1 classified Listing Plugin Wordpress Wordpress wordpress |
Tue, 11 Nov 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the "rtcl_ajax_add_listing_type", "rtcl_ajax_update_listing_type", and "rtcl_ajax_delete_listing_type" function in all versions up to, and including, 5.2.0. This makes it possible for authenticated attackers, with subscriber level access and above, to add, update, or delete listing types. | |
| Title | Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.2.0 - Missing Authorization to Authenticated (Subscriber+) Listing Types Tampering | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-11-14T15:29:30.681Z
Reserved: 2025-11-10T13:49:05.597Z
Link: CVE-2025-12953
Updated: 2025-11-14T15:20:49.114Z
Status : Awaiting Analysis
Published: 2025-11-11T11:15:35.230
Modified: 2025-11-12T16:19:34.210
Link: CVE-2025-12953
No data.
OpenCVE Enrichment
Updated: 2025-11-12T12:42:45Z