Impact
The Classified Listing WordPress plugin, before version 6.1.1, allows an authenticated user to trigger an AI image‑editing AJAX action that deletes or attaches media to any listing without verifying ownership or edit rights. As a result, a subscriber can permanently delete attachments from or attach arbitrary files to listings owned by other users, leading to loss of integrity and availability of media and enabling the insertion of potentially harmful content.
Affected Systems
WordPress sites that install the Classified Listing plugin in a release earlier than 6.1.1 are impacted. No other vendors or product versions are listed as affected.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so public exploitation data is limited. Nevertheless, the flaw constitutes a significant authorization bypass (IDOR) that permits non‑administrator users to modify listing content. The exploitation path requires the attacker to be authenticated, which is typically easy to achieve via legitimate login, and then to call the exposed AJAX endpoint. The impact is high due to the ability to alter or remove media and unintentionally import malicious files; however, no direct code execution is indicated.
OpenCVE Enrichment