Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ben Tamam

#54076of 56,335
4.3Total CVSS
Vulnerabilities · 1
PT-2026-50830
4.3
2026-06-19
WordPress · Classified Listing · CVE-2026-10779
**Name of the Vulnerable Software and Affected Versions** Classified Listing – Classified ads & Business Directory versions prior to 5.4.3 **Description** The plugin contains a missing authorization flaw in the `gallery image update as feature` AJAX handler (action: `rtcl fb gallery image update as feature`). The handler fails to perform capability or ownership checks when processing a user-supplied listing ID and attachment ID to set a featured image. Because it only validates a nonce available to any logged-in user on the frontend listing-submission form, authenticated attackers with Subscriber-level access or higher can change the featured image of listings they do not own. **Recommendations** Update the plugin to a version later than 5.4.2.