CVE-2026-16274 PUBLISHED

Classified Listing < 5.4.4 - Contributor+ Unpublished Post Content Disclosure via rtcl_block_css_get_posts

Assigner: WPScan
Reserved: 20.07.2026 Published: 03.08.2026 Updated: 03.08.2026

The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site — including drafts, pending, and private posts owned by other users — regardless of ownership.

Product Status

Vendor Unknown
Product Classified Listing
Versions Default: unaffected
  • affected from 0 to 5.4.4 (excl.)

Credits

  • Huseyin Mertoglu finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE