WordPress · Classified Listing · CVE-2026-14183
**Name of the Vulnerable Software and Affected Versions**
Classified Listing versions prior to 5.3.9
**Description**
An Insecure Direct Object Reference (IDOR) exists in the payment-receipt handler. The plugin fails to verify if the requested order belongs to the authenticated user, which allows users with subscriber-level access to view payment receipt details of orders belonging to other users.
**Recommendations**
Update Classified Listing to version 5.3.9 or later.