Description
Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.
Published: 2026-07-02
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a broken access control vulnerability in the WordPress Classified Listing plugin up to version 5.4.2. It allows an authenticated user with subscriber privileges to view, modify, or delete listings that should be restricted to higher‑privileged roles. This defect can be used to tamper with or delete legitimate listings, potentially leading to defacement, fraud, or disruption of the site’s content integrity.

Affected Systems

RadiusTheme:Classified Listing plugin versions <= 5.4.2 are affected. Any WordPress site that has installed these releases must verify the plugin version and apply an update if the plugin is present.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. A very low EPSS score (<1%) suggests that exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, attackers must first possess a subscriber account or successfully create one, so the attack vector is the web application with an existing user session. Once the attacker controls such an account, they can create, edit, or delete listings without proper authorization.

Generated by OpenCVE AI on August 1, 2026 at 21:44 UTC.

Remediation

Vendor Solution

Update the WordPress Classified Listing Plugin to the latest available version (at least 5.4.3).


OpenCVE Recommended Actions

  • Upgrade the Classified Listing plugin to version 5.4.3 or newer.
  • Ensure that only administrators or designated edit admins have edit/delete capabilities for listings; adjust subscriber role capabilities accordingly if the plugin allows configuration.
  • Enable detailed logging for listing CRUD operations and review audit logs regularly for anomalous activity.

Generated by OpenCVE AI on August 1, 2026 at 21:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Radiustheme
Radiustheme classified Listing
Wordpress
Wordpress wordpress
Vendors & Products Radiustheme
Radiustheme classified Listing
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.
Title WordPress Classified Listing plugin <= 5.4.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Radiustheme Classified Listing
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T14:58:13.199Z

Reserved: 2026-06-24T12:45:36.888Z

Link: CVE-2026-57355

cve-icon Vulnrichment

Updated: 2026-07-02T14:58:06.268Z

cve-icon NVD

Status : Deferred

Published: 2026-07-02T12:17:35.847

Modified: 2026-07-02T15:17:09.397

Link: CVE-2026-57355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T21:45:05Z

Weaknesses