Review
Classified Listing
CVE published 2026-08-03
CVE-2026-16274
The Classified Listing WordPress plugin before 5.4.4 has a vulnerability allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site, including drafts, pending, and private posts owned by other users. This issue arises from the plugin's failure to perform a capability or ownership check on an AJAX action that returns a post's content. As a [truncated]