WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds <= 4.4.8 - Unauthenticated Insecure Direct Object Reference to Listing Modification and Deletion via 'listing_id' Parameter
- ID
- WPSEC-2026-0537
- Plugin
- AWP Classifieds (another-wordpress-classifieds-plugin)
- Affected
- from 4.0.0 before 4.4.9
- Remediation
- Update to 4.4.9 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Weakness
- CWE-639
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds on WPSec AttackSurface
- Fix released
- Published
Description
The WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 4.0.0 up to, and including, 4.4.8. This is due to the Submit Listing page skipping its listing ownership check whenever any payment transaction is supplied with the request, without verifying that the transaction belongs to the requested listing. This makes it possible for unauthenticated attackers, on sites that allow ads to be posted without registration (the default), to open the Submit Listing page with another user's 'listing_id', view that listing's stored details including contact information, and obtain the security tokens the plugin accepts as authorization to edit it, which can be used to modify the listing and, in versions 4.4.5 and later, to delete it.
References
- https://wpsec.com/vuln/WPSEC-2026-0537/
- https://plugins.svn.wordpress.org/another-wordpress-classifieds-plugin/tags/4.4.9/
- https://wordpress.org/plugins/another-wordpress-classifieds-plugin/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS