CVE-2026-16276
N/A
N/A
Summary
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read daily revenue figures normally restricted to administrators and report managers.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Classified Listing | 0 < 5.4.4 | affected |
Weaknesses
- CWE-862 Missing Authorization
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.