CVE-2026-14183
Description
The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Unknown | Classified Listing | — | 0 < 5.3.9 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-639 Authorization Bypass Through User-Controlled Key |