CVE-2026-42679
Description
A path traversal vulnerability in the Classified Listing plugin for WordPress allows unauthenticated attackers to download arbitrary files from the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A path traversal vulnerability in the Classified Listing plugin for WordPress allows unauthenticated attackers to download arbitrary files from the server.
Vulnerability
The Classified Listing plugin for WordPress, in versions up to and including 5.3.8, contains an improper limitation of a pathname to a restricted directory, commonly known as path traversal. This vulnerability exists because the plugin fails to properly sanitize user-supplied input when handling file paths, allowing the application to access files outside of the intended directory structure [2].
Exploitation
An attacker can exploit this vulnerability by sending a specially crafted request to the affected WordPress site. No authentication or specific user privileges are required to trigger the path traversal, making it accessible to remote, unauthenticated actors who can manipulate the request parameters to traverse the filesystem and target sensitive files [2].
Impact
Successful exploitation allows an attacker to download arbitrary files from the underlying server. This can lead to the unauthorized disclosure of sensitive information, including configuration files, database credentials, or site backups, potentially resulting in a full compromise of the WordPress installation [2].
Mitigation
Users should update the Classified Listing plugin to version 5.3.9 or later to resolve this vulnerability [2]. If an immediate update is not possible, site administrators are advised to implement web application firewall rules to block malicious requests targeting file paths until the plugin can be patched [2].
AI Insight generated on Jun 1, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=5.3.8
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.