CVE-2026-14183 PUBLISHED

Classified Listing < 5.3.9 - Subscriber+ Payment Receipt Disclosure via IDOR

Assigner: WPScan
Reserved: 30.06.2026 Published: 21.07.2026 Updated: 21.07.2026

The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order.

Product Status

Vendor Unknown
Product Classified Listing
Versions Default: unaffected
  • affected from 0 to 5.3.9 (excl.)

Credits

  • PO-WEI TING (Dinlon5566) finder
  • Open Information Security Inc. finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE