Radiustheme
Radiustheme Classified Listing: vulnerabilidades y CVE
Radiustheme Classified Listing tiene 29 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE29
Últimos 12 meses15
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-96351 | Alta (7.1) | 0.18% | — | 30 sept 2026 | Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions. |
| CVE-2026-16281 | Alta (7.1) | 0.19% | — | 4 sept 2026 | The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated… |
| CVE-2026-84217 | Media (5.4) | 0.29% | — | 2 sept 2026 | Missing Authorization vulnerability in Mamunur Rashid Classified Listing classified-listing allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Classified Listing: from n/a through 6.1.3. |
| CVE-2026-16276 | Baja (2.7) | 0.30% | — | 3 ago 2026 | The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read… |
| CVE-2026-16274 | Baja (2.7) | 0.30% | — | 3 ago 2026 | The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the… |
| CVE-2026-14183 | Media (4.3) | 0.27% | — | 21 jul 2026 | The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to… |
| CVE-2026-57355 | Media (6.5) | 0.30% | — | 2 jul 2026 | Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions. |
| CVE-2026-57344 | Alta (7.1) | 0.25% | — | 2 jul 2026 | Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions. |
| CVE-2026-10779 | Media (4.3) | 0.37% | — | 19 jun 2026 | The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.4.2. This is due to a missing capability/ownership check… |
| CVE-2026-42658 | Alta (7.1) | 0.25% | — | 15 jun 2026 | Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.3.8 versions. |
| CVE-2026-42640 | Media (6.5) | 0.27% | — | 15 jun 2026 | Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions. |
| CVE-2026-42679 | Media (6.5) | 0.44% | — | 1 jun 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal. This issue affects Classified Listing: from n/a through 5.3.8. |
| CVE-2026-7563 | Media (4.3) | 0.45% | — | 15 may 2026 | The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.3.10. This is due to the plugin not… |
| CVE-2026-23546 | Media (6.5) | 0.37% | — | 5 mar 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in RadiusTheme Classified Listing classified-listing allows Retrieve Embedded Sensitive Data.This issue affects Classified Listing: from n/a through <=… |
| CVE-2025-7711 | Media (5.4) | 0.22% | — | 17 nov 2025 | The The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.3. This is due to the software… |
| CVE-2025-58601 | Media (4.3) | 0.24% | — | 3 sept 2025 | Missing Authorization vulnerability in RadiusTheme Classified Listing classified-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Classified Listing: from n/a through <=… |
| CVE-2025-54698 | Media (5.4) | 0.19% | — | 14 ago 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in RadiusTheme Classified Listing classified-listing allows Code Injection.This issue affects Classified Listing: from n/a… |
| CVE-2025-52715 | Alta (7.5) | 0.56% | — | 20 jun 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Classified Listing classified-listing allows PHP Local File Inclusion.This issue… |
| CVE-2025-24745 | Alta (7.1) | 0.29% | — | 17 abr 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Classified Listing classified-listing allows Reflected XSS.This issue affects Classified Listing: from… |
| CVE-2025-1063 | Media (5.3) | 0.36% | — | 25 feb 2025 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.4 via the rtcl_taxonomy_settings_export… |
| CVE-2024-11194 | Alta (8.8) | 0.56% | — | 19 nov 2024 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a misconfigured check on the… |
| CVE-2024-52386 | Media (5.3) | 0.47% | — | 16 nov 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Classified Listing classified-listing allows PHP Local File Inclusion.This issue… |
| CVE-2024-7888 | Media (4.3) | 0.29% | — | 13 sept 2024 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like export_forms(), import_forms(),… |
| CVE-2024-3893 | Media (4.3) | 0.36% | — | 25 abr 2024 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the rtcl_fb_gallery_image_delete AJAX action in… |
| CVE-2024-1352 | Media (5.3) | 0.55% | — | 9 abr 2024 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on the rtcl_import_location()… |
| CVE-2024-1315 | Alta (8.8) | 0.45% | — | 9 abr 2024 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. This is due to missing or incorrect nonce… |
| CVE-2023-37387 | Alta (8.8) | 0.25% | — | 18 jul 2023 | Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Classified Listing plugin <= 2.4.5 versions. |
| CVE-2022-2655 | Media (6.1) | 0.70% | — | 16 sept 2022 | The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting |
| CVE-2022-2654 | Media (6.1) | 0.62% | — | 16 sept 2022 | The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.