CVE-2026-16281
moderateBroken Authorization in Classified Listing WordPress Plugin Lets Subscribers Delete Listing Media
CVE-2026-16281 is a missing ownership/authorization check (CWE-639) in the AI image-editing AJAX action of the Classified Listing WordPress plugin. Because the action does not verify that the caller owns or can edit the target listing, any authenticated user — even a subscriber with the lowest role — can invoke it against listings belonging to other users. An attacker gains the ability to permanently delete attachments from, or attach files to, any listing on the site, corrupting or removing other users' listing media without needing elevated privileges. Sites running Classified Listing versions before 6.1.1 are affected. Exploitation is not currently known in the wild: there is no public proof-of-concept, EPSS estimates only a 0.2% chance of exploitation within 30 days, and the issue is not in CISA's KEV catalog.
What to do: Update Classified Listing to version 6.1.1 or later. Until patched, restrict subscriber registration or limit which roles can reach the AI image-editing AJAX action, and review listings and the media library for unexpected attachment deletions or added files. Since attackers only need a subscriber account, audit user registrations if the plugin runs on a site that allows public sign-up.
| Radius Theme Classified Listing (WordPress plugin) | All versions before 6.1.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing owned by another user.
- Ecosystems
- WordPress
- Weakness
- CWE-639
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.