Classified Listing – AI-Powered Classified ads & Business Directory

Information

Software Type Plugin
Software Slug classified-listing (view on wordpress.org)
Software Status Active
Software Author techlabpro1
Software Website radiustheme.com
Software Downloads 672,052
Software Active Installs 9,000
Software Record Last Updated August 18, 2026

Showing 1-20 of 26 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Classified Listing – Classified ads & Business Directory Plugin <= 3.1.15.1 - Authenticated (Subscriber+) Limited Arbitrary Option Update Patched CVE-2024-11194 8.8 vgo0 November 18, 2024
Classified Listing <= 3.1.16 - Authenticated (Contributor+) Local File Inclusion Patched CVE-2024-52386 8.8 João Pedro Soares de Alcântara November 11, 2024
Classified Listing <= 3.0.4 - Cross-Site Request Forgery to Account Takeover via rtcl_update_user_account Patched CVE-2024-1315 8.8 Francesco Carlucci April 4, 2024
Classified Listing – AI-Powered Classified ads & Business Directory <= 5.4.2 - Unauthenticated Stored Cross-Site Scripting Patched CVE-2026-57344 7.2 daroo June 29, 2026
Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.8 - Unauthenticated Stored Cross-Site Scripting Patched CVE-2026-42658 7.2 endy April 29, 2026
Classified Listing – Classified ads & Business Directory Plugin <= 3.0.4 - Missing Authorization Patched CVE-2024-1352 6.5 Francesco Carlucci April 4, 2024
Classified Listing – Classified ads & Business Directory Plugin <= 3.1.7 - Missing Authorization Patched CVE-2024-7888 6.3 Lucio Sá September 12, 2024
Classified Listing – Classified ads & Business Directory Plugin <= 4.0.1 - Reflected Cross-Site Scripting Patched CVE-2025-24745 6.1 Le Ngoc Anh October 27, 2024
Classima < 2.1.11 - Reflected Cross-Site Scripting Patched CVE-2022-2654 6.1 Team ISH Tecnologia, Islan Ferreira August 22, 2022
Classified Listing – Classified ads & Business Directory Plugin <= 5.0.3 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via Listing Description Patched CVE-2025-7711 5.4 Kishan Vyas November 17, 2025
Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.8 - Missing Authorization Patched CVE-2026-42640 5.3 Cruzer April 29, 2026
Classified Listing – Classified ads & Business Directory Plugin <= 4.0.4 - Unauthenticated Settings Exposure Patched CVE-2025-1063 5.3 wesley (wcraft) February 24, 2025
Classified Listing <= 5.4.3 - Missing Authorization Patched CVE-2026-16276 4.3 Huseyin Mertoglu July 23, 2026
Classified Listing <= 5.4.3 - Missing Authorization Patched CVE-2026-16274 4.3 Huseyin Mertoglu July 23, 2026
Classified Listing – AI-Powered Classified ads & Business Directory <= 5.4.2 - Missing Authorization Patched CVE-2026-57355 4.3 Septio Noerdiansyah July 1, 2026
Classified Listing <= 5.3.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Receipt Disclosure Patched CVE-2026-14183 4.3 PO-WEI TING (Dinlon5566) , Open Information Security Inc. June 30, 2026
Classified Listing <= 5.4.2 - Missing Authorization to Authenticated (Subscriber+) Feature Modification via Multiple AJAX Handlers ('listingId'/'id' Parameters) Patched CVE-2026-10779 4.3 Ben Tamam (Ben Tamam) June 18, 2026
Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.8 - Authenticated (Subscriber+) Arbitrary File Download Patched CVE-2026-42679 4.3 thevietronin May 17, 2026
Classified Listing <= 5.3.10 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via add_order_note and send_email_to_user_by_moderator AJAX Actions Patched CVE-2026-7563 4.3 momopon1415 May 14, 2026
Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.9 - Missing Authorization Patched CVE-2026-42651 4.3 Jakub Herman April 29, 2026

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation