CVE-2026-16274: CWE-862 Missing Authorization in Classified Listing
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site — including drafts, pending, and private posts owned by other users — regardless of ownership.
AI Analysis
Technical Summary
CVE-2026-16274 is a vulnerability in the Classified Listing WordPress plugin where an AJAX action that returns post content does not perform capability or ownership checks. As a result, authenticated users with contributor-level permissions or above can access the content of any post, page, or custom post type on the site, including those that are drafts, pending, or private and owned by other users. This issue arises from missing authorization controls (CWE-862).
Potential Impact
The vulnerability allows unauthorized reading of post content by users who should not have access, potentially exposing sensitive or private information. However, it does not allow modification or deletion of content. The CVSS score is low (2.7), reflecting limited impact confined to confidentiality with no integrity or availability impact.
Mitigation Recommendations
No official patch or remediation guidance is currently available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, restrict contributor-level access carefully and monitor user permissions to limit exposure.
CVE-2026-16274: CWE-862 Missing Authorization in Classified Listing
Description
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site — including drafts, pending, and private posts owned by other users — regardless of ownership.
CVSS v3.1
Score 2.7low
Affected software
Classified Listing
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-16274 is a vulnerability in the Classified Listing WordPress plugin where an AJAX action that returns post content does not perform capability or ownership checks. As a result, authenticated users with contributor-level permissions or above can access the content of any post, page, or custom post type on the site, including those that are drafts, pending, or private and owned by other users. This issue arises from missing authorization controls (CWE-862).
Potential Impact
The vulnerability allows unauthorized reading of post content by users who should not have access, potentially exposing sensitive or private information. However, it does not allow modification or deletion of content. The CVSS score is low (2.7), reflecting limited impact confined to confidentiality with no integrity or availability impact.
Mitigation Recommendations
No official patch or remediation guidance is currently available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, restrict contributor-level access carefully and monitor user permissions to limit exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-20T10:04:01.162Z
- State
- PUBLISHED
Threat ID: 6a70364ebf32cb7a34183121
Added to database: 08/03/2026, 06:33:50 UTC
Last enriched: 08/10/2026, 14:47:18 UTC
Last updated: 09/17/2026, 22:01:33 UTC
Views: 37
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.