Description
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site — including drafts, pending, and private posts owned by other users — regardless of ownership.
Published: 2026-08-03
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Classified Listing WordPress plugin allows users with contributor-level access or higher to retrieve the full content of any post, page, or custom post type, including drafts, pending, and private posts, by exploiting an AJAX action that lacks proper capability or ownership verification. The flaw results in unauthorized disclosure of potentially sensitive or unpublished content, thereby compromising confidentiality.

Affected Systems

Any site running the Classified Listing plugin before version 5.4.4 on WordPress is affected. No specific vendor or product versions beyond that cutoff are listed; the issue applies to all earlier releases of this plugin.

Risk and Exploitability

Because the exploitation requires only an authenticated contributor account, an attacker who has legitimately logged in with such a role can easily trigger the vulnerable AJAX endpoint. No elevated privileges or additional exploits are needed. The CVSS score is 2.7, indicating a low severity, and the EPSS score is <1%, reflecting a low likelihood of exploitation. Despite the low scores, the vulnerability still poses a confidentiality risk, especially in environments with many contributors. The issue is not yet listed in CISA's KEV catalog.

Generated by OpenCVE AI on August 4, 2026 at 21:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Classified Listing to version 5.4.4 or later, which includes the missing authorization check.
  • If an immediate upgrade is not possible, restrict contributor accounts, or disable the rtcl_block_css_get_posts AJAX action via firewall or server rule.
  • Verify that only required roles have contributor permissions and consider removing contributor role before publishing.

Generated by OpenCVE AI on August 4, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 03 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site — including drafts, pending, and private posts owned by other users — regardless of ownership.
Title Classified Listing < 5.4.4 - Contributor+ Unpublished Post Content Disclosure via rtcl_block_css_get_posts
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-04T17:41:58.702Z

Reserved: 2026-07-20T10:04:01.162Z

Link: CVE-2026-16274

cve-icon Vulnrichment

Updated: 2026-08-04T15:54:08.874Z

cve-icon NVD

Status : Received

Published: 2026-08-03T07:16:41.020

Modified: 2026-08-04T18:16:46.450

Link: CVE-2026-16274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T21:30:12Z

Weaknesses