PatchSiren

Classified Listing CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Classified Listing CVE published 2026-08-03

CVE-2026-16274

The Classified Listing WordPress plugin before 5.4.4 has a vulnerability allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site, including drafts, pending, and private posts owned by other users. This issue arises from the plugin's failure to perform a capability or ownership check on an AJAX action that returns a post's content. As a [truncated]