WordPress Plugin Vulnerabilities

Classified Listing < 5.3.9 - Subscriber+ Payment Receipt Disclosure via IDOR

Description

The plugin does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order.

Proof of Concept

Affects Plugins

Fixed in 5.3.9

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
PO-WEI TING (Dinlon5566) , Open Information Security Inc.
Submitter
PO-WEI TING (Dinlon5566)
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-06-30 (about 1 month ago)
Added
2026-06-30 (about 1 month ago)
Last Updated
2026-06-30 (about 1 month ago)

Other