WordPress Plugin Vulnerabilities

Classified Listing < 6.1.1 - Subscriber+ Arbitrary Attachment Deletion and Listing Image Tampering via IDOR

Description

The plugin does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing owned by another user.

Proof of Concept

Affects Plugins

Fixed in 6.1.1

References

Classification

Type
IDOR
CWE
CVSS

Miscellaneous

Original Researcher
Usama Arshad
Submitter
Usama Arshad
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-09-02 (about 2 days ago)
Added
2026-09-02 (about 1 day ago)
Last Updated
2026-09-02 (about 1 day ago)

Other