« Volver al listado

Radiustheme

Radiustheme Classified Listing: vulnerabilidades y CVE

Radiustheme Classified Listing tiene 29 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE29
Últimos 12 meses15
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-96351Alta (7.1)0.18%—30 sept 2026
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions.
CVE-2026-16281Alta (7.1)0.19%—4 sept 2026
The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated…
CVE-2026-84217Media (5.4)0.29%—2 sept 2026
Missing Authorization vulnerability in Mamunur Rashid Classified Listing classified-listing allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Classified Listing: from n/a through 6.1.3.
CVE-2026-16276Baja (2.7)0.30%—3 ago 2026
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read…
CVE-2026-16274Baja (2.7)0.30%—3 ago 2026
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the…
CVE-2026-14183Media (4.3)0.27%—21 jul 2026
The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to…
CVE-2026-57355Media (6.5)0.30%—2 jul 2026
Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.
CVE-2026-57344Alta (7.1)0.25%—2 jul 2026
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions.
CVE-2026-10779Media (4.3)0.37%—19 jun 2026
The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.4.2. This is due to a missing capability/ownership check…
CVE-2026-42658Alta (7.1)0.25%—15 jun 2026
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.3.8 versions.
CVE-2026-42640Media (6.5)0.27%—15 jun 2026
Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions.
CVE-2026-42679Media (6.5)0.44%—1 jun 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal. This issue affects Classified Listing: from n/a through 5.3.8.
CVE-2026-7563Media (4.3)0.45%—15 may 2026
The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.3.10. This is due to the plugin not…
CVE-2026-23546Media (6.5)0.37%—5 mar 2026
Insertion of Sensitive Information Into Sent Data vulnerability in RadiusTheme Classified Listing classified-listing allows Retrieve Embedded Sensitive Data.This issue affects Classified Listing: from n/a through <=…
CVE-2025-7711Media (5.4)0.22%—17 nov 2025
The The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.3. This is due to the software…
CVE-2025-58601Media (4.3)0.24%—3 sept 2025
Missing Authorization vulnerability in RadiusTheme Classified Listing classified-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Classified Listing: from n/a through <=…
CVE-2025-54698Media (5.4)0.19%—14 ago 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in RadiusTheme Classified Listing classified-listing allows Code Injection.This issue affects Classified Listing: from n/a…
CVE-2025-52715Alta (7.5)0.56%—20 jun 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Classified Listing classified-listing allows PHP Local File Inclusion.This issue…
CVE-2025-24745Alta (7.1)0.29%—17 abr 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Classified Listing classified-listing allows Reflected XSS.This issue affects Classified Listing: from…
CVE-2025-1063Media (5.3)0.36%—25 feb 2025
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.4 via the rtcl_taxonomy_settings_export…
CVE-2024-11194Alta (8.8)0.56%—19 nov 2024
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a misconfigured check on the…
CVE-2024-52386Media (5.3)0.47%—16 nov 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Classified Listing classified-listing allows PHP Local File Inclusion.This issue…
CVE-2024-7888Media (4.3)0.29%—13 sept 2024
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like export_forms(), import_forms(),…
CVE-2024-3893Media (4.3)0.36%—25 abr 2024
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the rtcl_fb_gallery_image_delete AJAX action in…
CVE-2024-1352Media (5.3)0.55%—9 abr 2024
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on the rtcl_import_location()…
CVE-2024-1315Alta (8.8)0.45%—9 abr 2024
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. This is due to missing or incorrect nonce…
CVE-2023-37387Alta (8.8)0.25%—18 jul 2023
Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Classified Listing plugin <= 2.4.5 versions.
CVE-2022-2655Media (6.1)0.70%—16 sept 2022
The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
CVE-2022-2654Media (6.1)0.62%—16 sept 2022
The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.007 JavaScript4
  2. T1189 Drive-by Compromise4
  3. T1210 Exploitation of Remote Services3
  4. T1078 Valid Accounts1
  5. T1565.001 Stored Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Radiustheme