CVE-2026-16274
Received Received - Intake

Classified Listing Post Content Exposure via AJAX

Vulnerability report for CVE-2026-16274, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: WPScan

Description

The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site β€” including drafts, pending, and private posts owned by other users β€” regardless of ownership.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
classified_listing wordpress_plugin to 5.4.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Classified Listing WordPress plugin before version 5.4.4 has a vulnerability where an AJAX action does not check user capabilities or ownership before returning a post's content. This allows users with contributor-level access or higher to read any post, page, or custom post type on the site, including drafts, pending, and private posts owned by others.

Detection Guidance

Check if the Classified Listing WordPress plugin version is below 5.4.4. Inspect network traffic for unauthorized AJAX requests to retrieve post content. Review user roles with contributor-level access or higher for unusual activity.

Impact Analysis

This vulnerability could allow unauthorized users to access sensitive or confidential content on your WordPress site, including private drafts or posts they should not see. It compromises data confidentiality and could lead to information leaks or misuse of restricted content.

Compliance Impact

This vulnerability may violate compliance requirements such as GDPR or HIPAA by exposing protected or sensitive data to unauthorized users. It undermines data protection measures and could result in regulatory penalties or loss of trust.

Mitigation Strategies

Update the Classified Listing plugin to version 5.4.4 or later. Remove or restrict contributor-level access to only trusted users. Monitor for unauthorized access to draft, pending, or private posts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16274. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart