VYPR

Classified Listing

by WordPress

Source repositories

CVEs (28)

  • CVE-2026-7563MedMay 15, 2026
    risk 0.21cvss 4.3epss 0.00

    The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.3.10. This is due to the plugin not properly verifying that a user is authorized to perform an…

  • CVE-2025-12953MedNov 11, 2025
    risk 0.21cvss 4.3epss 0.00

    The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the "rtcl_ajax_add_listing_type", "rtcl_ajax_update_listing_type", and…

  • CVE-2024-3893MedApr 25, 2024
    risk 0.21cvss 4.3epss 0.00

    The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the rtcl_fb_gallery_image_delete AJAX action in all versions up to, and including, 3.0.10.3. This makes it…

  • CVE-2026-16276LowAug 3, 2026
    risk 0.00cvss 2.7epss 0.00

    The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read daily revenue figures normally restricted to administrators…

  • CVE-2026-16274LowAug 3, 2026
    risk 0.00cvss 2.7epss 0.00

    The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site…

  • CVE-2026-14183MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order.

  • CVE-2026-57355MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.

  • CVE-2026-57344HigJul 2, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions.

Page 2 of 2