The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the "rtcl_ajax_add_listing_type", "rtcl_ajax_update_listing_type", and "rtcl_ajax_delete_listing_type" function in all versions up to, and including, 5.2.0. This makes it possible for authenticated attackers, with subscriber level access and above, to add, update, or delete listing types.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Techlabpro1
Techlabpro1 classified Listing Plugin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Techlabpro1
Techlabpro1 classified Listing Plugin Wordpress Wordpress wordpress |
Tue, 11 Nov 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the "rtcl_ajax_add_listing_type", "rtcl_ajax_update_listing_type", and "rtcl_ajax_delete_listing_type" function in all versions up to, and including, 5.2.0. This makes it possible for authenticated attackers, with subscriber level access and above, to add, update, or delete listing types. | |
| Title | Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.2.0 - Missing Authorization to Authenticated (Subscriber+) Listing Types Tampering | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-11-11T11:03:45.759Z
Updated: 2025-11-14T15:29:30.681Z
Reserved: 2025-11-10T13:49:05.597Z
Link: CVE-2025-12953
Updated: 2025-11-14T15:20:49.114Z
Status : Awaiting Analysis
Published: 2025-11-11T11:15:35.230
Modified: 2025-11-12T16:19:34.210
Link: CVE-2025-12953
No data.
ReportizFlow