WordPress · Classified Listing · CVE-2026-10779
**Name of the Vulnerable Software and Affected Versions**
Classified Listing – Classified ads & Business Directory versions prior to 5.4.3
**Description**
The plugin contains a missing authorization flaw in the `gallery image update as feature` AJAX handler (action: `rtcl fb gallery image update as feature`). The handler fails to perform capability or ownership checks when processing a user-supplied listing ID and attachment ID to set a featured image. Because it only validates a nonce available to any logged-in user on the frontend listing-submission form, authenticated attackers with Subscriber-level access or higher can change the featured image of listings they do not own.
**Recommendations**
Update the plugin to a version later than 5.4.2.