WordPress · Classified Listing · CVE-2026-16274
**Name of the Vulnerable Software and Affected Versions**
Classified Listing WordPress plugin versions prior to 5.4.4
**Description**
An AJAX action that returns post content fails to perform necessary capability or ownership checks. This allows users with contributor-level access or higher to read the content of any post, page, or custom post type on the site, including private, pending, and draft content owned by other users.
**Recommendations**
Update the Classified Listing WordPress plugin to version 5.4.4 or later.