What is CVE-2026-16274?
CVE-2026-16274 exists in the 'Classified Listing' WordPress plugin before version 5.4.4. Due to a missing capability or ownership check on an AJAX action, users with contributor-level access and above can read the content of any post, page, or custom post type, including drafts. Updating the plugin to version 5.4.4 or later is recommended.
Azərbaycanca: CVE-2026-16274 'Classified Listing' WordPress plugin-inin 5.4.4-dən əvvəlki versiyalarında tapılıb. Zəiflik AJAX əməliyyatında səlahiyyət yoxlanışının olmaması səbəbindən contributor və yuxarı rol sahiblərinə saytdakı istənilən postun, o cümlədən qaralamaların məzmununu oxumağa imkan verir. Plugin-i 5.4.4 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which user roles can exploit the CVE-2026-16274 vulnerability?
This vulnerability can be exploited by users with contributor-level access and above, such as authors and editors.
What kind of data can be accessed through CVE-2026-16274?
It allows reading the content of any post, page, or custom post type, including drafts.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.