Impact
The vulnerability in the Classified Listing WordPress plugin allows users with contributor-level access or higher to retrieve the full content of any post, page, or custom post type, including drafts, pending, and private posts, by exploiting an AJAX action that lacks proper capability or ownership verification. The flaw results in unauthorized disclosure of potentially sensitive or unpublished content, thereby compromising confidentiality.
Affected Systems
Any site running the Classified Listing plugin before version 5.4.4 on WordPress is affected. No specific vendor or product versions beyond that cutoff are listed; the issue applies to all earlier releases of this plugin.
Risk and Exploitability
Because the exploitation requires only an authenticated contributor account, an attacker who has legitimately logged in with such a role can easily trigger the vulnerable AJAX endpoint. No elevated privileges or additional exploits are needed. The CVSS score is 2.7, indicating a low severity, and the EPSS score is <1%, reflecting a low likelihood of exploitation. Despite the low scores, the vulnerability still poses a confidentiality risk, especially in environments with many contributors. The issue is not yet listed in CISA's KEV catalog.
OpenCVE Enrichment