CVE-2026-16281 PUBLISHED

Classified Listing < 6.1.1 - Subscriber+ Arbitrary Attachment Deletion and Listing Image Tampering via IDOR

Assigner: WPScan
Reserved: 20.07.2026 Published: 04.09.2026 Updated: 04.09.2026

The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing owned by another user.

Product Status

Vendor Unknown
Product Classified Listing
Versions Default: unaffected
  • affected from 5.3.0 to 6.1.1 (excl.)

Credits

  • Usama Arshad finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE