PT-2026-67104 · WordPress · Classified Listing

·

CVE-2026-16276

·

Published

2026-08-03

·

Updated

2026-08-04

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Classified Listing WordPress plugin versions prior to 5.4.4
Description An issue exists where a capability check is not performed on an AJAX action that returns aggregated store revenue totals. This allows users with contributor-level access and above to read daily revenue figures that are normally restricted to administrators and report managers.
Recommendations Update the Classified Listing WordPress plugin to version 5.4.4 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16276

Affected Products

Classified Listing