Plugin Vulnerability Hub
Plugin 19 known issues Latest disclosed May 14, 2026

Classified Listing – AI-Powered Classified ads & Business Directory Plugin Vulnerabilities

Review known vulnerability records for the WordPress plugin Classified Listing – AI-Powered Classified ads & Business Directory Plugin (`classified-listing`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-7563, CVE-2026-42640 and CVE-2026-42651, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
19
High or Critical
5
Patch Coverage
100%
Last Updated
May 14, 2026
Related Security Guides

Use these guides while reviewing Classified Listing – AI-Powered Classified ads & Business Directory Plugin fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize Classified Listing – AI-Powered Classified ads & Business Directory Plugin remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
19
1. Match the Package
Confirm the installed WordPress plugin slug is classified-listing before acting on any CVE from this cluster.
2. Sort by Severity
Start with 5 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
19 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into Classified Listing – AI-Powered Classified ads & Business Directory Plugin CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
19
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2025-52715
Classified Listing <= 4.2.0 - Authenticated (Contributor+) Local File Inclusion
Local File Inclusion Versions up to 4.2.0 4.2.1 CVSS 8.8
CVE-2024-11194
Classified Listing – Classified ads & Business Directory Plugin <= 3.1.15.1 - Authen...
Privilege Escalation Versions up to 3.1.15.1 3.1.16 CVSS 8.8
CVE-2024-52386
Classified Listing <= 3.1.16 - Authenticated (Contributor+) Local File Inclusion
Local File Inclusion Versions up to 3.1.16 3.1.17 CVSS 8.8
CVE-2024-1315
Classified Listing <= 3.0.4 - Cross-Site Request Forgery to Account Takeover via rtc...
Cross-Site Request Forgery Versions up to 3.0.4 3.0.5 CVSS 8.8
CVE-2026-42658
Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.8...
Stored Cross-Site Scripting Versions up to 5.3.8 5.3.9 CVSS 7.2
CVE-2024-1352
Classified Listing – Classified ads & Business Directory Plugin <= 3.0.4 - Missing A...
Vulnerability Versions up to 3.0.4 3.0.5 CVSS 6.5
CVE-2024-7888
Classified Listing – Classified ads & Business Directory Plugin <= 3.1.7 - Missing A...
Vulnerability Versions up to 3.1.7 3.1.8 CVSS 6.3
CVE-2025-24745
Classified Listing – Classified ads & Business Directory Plugin <= 4.0.1 - Reflected...
Cross-Site Scripting Versions up to 4.0.1 4.0.2 CVSS 6.1
CVE-2025-52715 High 4.2.1
CVE-2025-52715 Classified Listing – AI-Powered Classified ads & Business Directory Plugin Local File Inclusion

Classified Listing <= 4.2.0 - Authenticated (Contributor+) Local File Inclusion

CVE-2024-11194 High 3.1.16
CVE-2024-11194 Classified Listing – AI-Powered Classified ads & Business Directory Plugin Privilege Escalation

Classified Listing – Classified ads & Business Directory Plugin <= 3.1.15.1 - Authenticated (Subscriber+) Limited Arbitrary Option Update

CVE-2024-52386 High 3.1.17
CVE-2024-52386 Classified Listing – AI-Powered Classified ads & Business Directory Plugin Local File Inclusion

Classified Listing <= 3.1.16 - Authenticated (Contributor+) Local File Inclusion

CVE-2024-1315 High 3.0.5
CVE-2024-1315 Classified Listing – AI-Powered Classified ads & Business Directory Plugin Cross-Site Request Forgery

Classified Listing <= 3.0.4 - Cross-Site Request Forgery to Account Takeover via rtcl_update_user_account

CVE-2026-42658 High 5.3.9
CVE-2026-42658 Classified Listing – AI-Powered Classified ads & Business Directory Plugin Stored Cross-Site Scripting

Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.8 - Unauthenticated Stored Cross-Site Scripting

CVE-2024-1352 Medium 3.0.5
CVE-2024-1352 Classified Listing – AI-Powered Classified ads & Business Directory Plugin Vulnerability

Classified Listing – Classified ads & Business Directory Plugin <= 3.0.4 - Missing Authorization

CVE-2024-7888 Medium 3.1.8
CVE-2024-7888 Classified Listing – AI-Powered Classified ads & Business Directory Plugin Vulnerability

Classified Listing – Classified ads & Business Directory Plugin <= 3.1.7 - Missing Authorization

CVE-2025-24745 Medium 4.0.2
CVE-2025-24745 Classified Listing – AI-Powered Classified ads & Business Directory Plugin Cross-Site Scripting

Classified Listing – Classified ads & Business Directory Plugin <= 4.0.1 - Reflected Cross-Site Scripting

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for Classified Listing – AI-Powered Classified ads & Business Directory Plugin so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
19 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 5 high severity findings.
Recent CVEs
CVE-2026-7563, CVE-2026-42640 and CVE-2026-42651
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

CVE-2026-7563 Medium Patch path listed

CVE-2026-7563: Classified Listing <= 5.3.10 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via add_order_note and send_email_to_user_by_moderator AJAX Actions

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.3.10. This is...

Published
May 14, 2026
Patch Status
5.4.0
Known Vulnerabilities

Reports for Classified Listing – AI-Powered Classified ads & Business Directory Plugin

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-7563
CVE-2026-7563: Classified Listing <= 5.3.10 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via add_order_note and send_email_to_user_by_moderator AJAX Actions

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.3.10. This is due to the plugin not properly verifying that a user is authorized to perform an action....

Published
May 14, 2026
Patched Release
5.4.0
Affected Versions
Versions up to 5.3.10
Next Step
Update to 5.4.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-42640
CVE-2026-42640: Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.8 - Missing Authorization

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.3.8. This makes it possible for unauthenticated attackers t...

Published
Apr 29, 2026
Patched Release
5.3.9
Affected Versions
Versions up to 5.3.8
Next Step
Update to 5.3.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-42651
CVE-2026-42651: Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.9 - Missing Authorization

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.3.9. This makes it possible for authenticated attackers, wi...

Published
Apr 29, 2026
Patched Release
5.3.10
Affected Versions
Versions up to 5.3.9
Next Step
Update to 5.3.10 or newer if supported.
Plugin High Patched: Yes CVE-2026-42658
CVE-2026-42658: Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.8 - Unauthenticated Stored Cross-Site Scripting

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthen...

Published
Apr 29, 2026
Patched Release
5.3.9
Affected Versions
Versions up to 5.3.8
Next Step
Update to 5.3.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-23546
CVE-2026-23546: Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.4 - Authenticated (Subscriber+) Sensitive Data Exposure

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with Subscriber-level access and ab...

Published
Feb 23, 2026
Patched Release
5.3.5
Affected Versions
Versions up to 5.3.4
Next Step
Update to 5.3.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-7711
CVE-2025-7711: Classified Listing – Classified ads & Business Directory Plugin <= 5.0.3 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via Listing Description

The The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.3. This is due to the software allowing users to execute an action that does not properly validate...

Published
Nov 17, 2025
Patched Release
5.0.4
Affected Versions
Versions up to 5.0.3
Next Step
Update to 5.0.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-12953
CVE-2025-12953: Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.2.0 - Missing Authorization to Authenticated (Subscriber+) Listing Types Tampering

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the "rtcl_ajax_add_listing_type", "rtcl_ajax_update_listing_type", and "rtcl_ajax_delete_lis...

Published
Nov 10, 2025
Patched Release
5.2.1
Affected Versions
Versions up to 5.2.0
Next Step
Update to 5.2.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-58601
CVE-2025-58601: Classified Listing <= 5.0.6 - Missing Authorization

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.0.6. This makes it possible for authenticated attackers...

Published
Sep 03, 2025
Patched Release
5.0.7
Affected Versions
Versions up to 5.0.6
Next Step
Update to 5.0.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-54698
CVE-2025-54698: Classified Listing <= 5.0.0 - Authenticated (Contributor+) Content Injection

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Content Injection in all versions up to, and including, 5.0.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrar...

Published
Jul 30, 2025
Patched Release
5.0.1
Affected Versions
Versions up to 5.0.0
Next Step
Update to 5.0.1 or newer if supported.
Plugin High Patched: Yes CVE-2025-52715
CVE-2025-52715: Classified Listing <= 4.2.0 - Authenticated (Contributor+) Local File Inclusion

The Classified Listing plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.0. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing t...

Published
Jun 19, 2025
Patched Release
4.2.1
Affected Versions
Versions up to 4.2.0
Next Step
Update to 4.2.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-1063
CVE-2025-1063: Classified Listing – Classified ads & Business Directory Plugin <= 4.0.4 - Unauthenticated Settings Exposure

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.4 via the rtcl_taxonomy_settings_export function. This makes it possible for unauthenticated attacker...

Published
Feb 24, 2025
Patched Release
4.0.5
Affected Versions
Versions up to 4.0.4
Next Step
Update to 4.0.5 or newer if supported.
Plugin High Patched: Yes CVE-2024-11194
CVE-2024-11194: Classified Listing – Classified ads & Business Directory Plugin <= 3.1.15.1 - Authenticated (Subscriber+) Limited Arbitrary Option Update

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a misconfigured check on the 'rtcl_import_settings' function in all versions up to, and includi...

Published
Nov 18, 2024
Patched Release
3.1.16
Affected Versions
Versions up to 3.1.15.1
Next Step
Update to 3.1.16 or newer if supported.