GHSA-6phg-rm29-h3wqMediumCVSS 4.3

The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by...

Published
July 21, 2026
Last Modified
July 21, 2026

🔗 CVE IDs covered (1)

📋 Description

The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order.

🔗 References (3)