Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 14 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Techlabpro1
Techlabpro1 classified Listing Plugin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Techlabpro1
Techlabpro1 classified Listing Plugin Wordpress Wordpress wordpress |
Tue, 11 Nov 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the "rtcl_ajax_add_listing_type", "rtcl_ajax_update_listing_type", and "rtcl_ajax_delete_listing_type" function in all versions up to, and including, 5.2.0. This makes it possible for authenticated attackers, with subscriber level access and above, to add, update, or delete listing types. | |
| Title | Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.2.0 - Missing Authorization to Authenticated (Subscriber+) Listing Types Tampering | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-11-14T15:29:30.681Z
Reserved: 2025-11-10T13:49:05.597Z
Link: CVE-2025-12953
Updated: 2025-11-14T15:20:49.114Z
Status : Awaiting Analysis
Published: 2025-11-11T11:15:35.230
Modified: 2025-11-12T16:19:34.210
Link: CVE-2025-12953
No data.
OpenCVE Enrichment
Updated: 2025-11-12T12:42:45Z