SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16281

HIGH · CVSS 7.1 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Classified Listing WordPress plugin prior to version 6.1.1 is vulnerable as it fails to verify user permissions when executing AI image-editing AJAX actions, allowing any authenticated user to delete or attach media to listings owned by others. This oversight can lead to unauthorized data loss and manipulation of content, posing a significant risk to site integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-16281
Severity
HIGH
CVSS
7.1
EPSS
0.19%
WordPress

Original NVD Description

The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing owned by another user.