CyberRota Analysis
AI-GeneratedThe Classified Listing WordPress plugin prior to version 6.1.1 is vulnerable as it fails to verify user permissions when executing AI image-editing AJAX actions, allowing any authenticated user to delete or attach media to listings owned by others. This oversight can lead to unauthorized data loss and manipulation of content, posing a significant risk to site integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.
Original NVD Description
The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing owned by another user.