Classified Listing – Classified ads & Business Directory Plugin, CVE-2026-14183
- CVE, Research URL
- Home page URL
-
Security reports for Classified Listing – Classified ads & Business Directory Plugin
- Published on
- Jul 21, 2026
- Research Description
- The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order.
- Affected versions
-
max 5.3.9.
- Status
-
vulnerable