ZeroHour

CVE-2026-16281

moderate

Broken Authorization in Classified Listing WordPress Plugin Lets Subscribers Delete Listing Media

CVSS 3.1
7.1 high
EPSS
<1%p9
Published
()
Modified
AI analysis

CVE-2026-16281 is a missing ownership/authorization check (CWE-639) in the AI image-editing AJAX action of the Classified Listing WordPress plugin. Because the action does not verify that the caller owns or can edit the target listing, any authenticated user — even a subscriber with the lowest role — can invoke it against listings belonging to other users. An attacker gains the ability to permanently delete attachments from, or attach files to, any listing on the site, corrupting or removing other users' listing media without needing elevated privileges. Sites running Classified Listing versions before 6.1.1 are affected. Exploitation is not currently known in the wild: there is no public proof-of-concept, EPSS estimates only a 0.2% chance of exploitation within 30 days, and the issue is not in CISA's KEV catalog.

What to do: Update Classified Listing to version 6.1.1 or later. Until patched, restrict subscriber registration or limit which roles can reach the AI image-editing AJAX action, and review listings and the media library for unexpected attachment deletions or added files. Since attackers only need a subscriber account, audit user registrations if the plugin runs on a site that allows public sign-up.

Affected
Radius Theme Classified Listing (WordPress plugin)All versions before 6.1.1
Estimated exposure
moderate≈10,000–20,000 sites (free plugin shows roughly 10k+ active installs on WordPress.org) — Classified Listing is a niche free directory plugin with a WordPress.org active-install count on the order of 10,000+, and only sites with open subscriber registration and active listings are meaningfully exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing owned by another user.

Ecosystems
WordPress
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

In the news

No ingested article mentions this CVE yet.