CVE-2026-7563
The Classified Listing - AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to una
The Classified Listing - AI-Powered Classified ads & Business Directory Plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.3.10. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to add arbitrary notes to any order and trigger unsolicited notification and moderation emails to listing owners without administrative authorization.
MEDIUM · CVSS 4.3
EPSS 0.00042
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0