What is CVE-2026-16276?
CVE-2026-16276 is a vulnerability in the Classified Listing WordPress plugin versions before 5.4.4. Due to missing capability checks on an AJAX action, users with contributor-level access or higher can view aggregated daily store revenue totals normally restricted to administrators. Updating to version 5.4.4 mitigates this issue.
Azərbaycanca: CVE-2026-16276, Classified Listing WordPress plagininin 5.4.4 versiyasından əvvəlki versiyalarında tapılan bir boşluqdur. Bu boşluq, AJAX əməliyyatı üzərində icazə yoxlaması aparılmadığı üçün contributor səviyyəsindən yuxarı girişi olan istifadəçilərə yalnız inzibatçılara açıq olan gündəlik mağaza gəlir məlumatlarını oxumağa imkan verir. Plagin 5.4.4 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which WordPress plugin is affected by CVE-2026-16276?
This vulnerability affects versions of the Classified Listing plugin prior to 5.4.4.
What access level can exploit CVE-2026-16276 to view restricted data?
Users with contributor-level access or higher can exploit this to view daily store revenue totals normally restricted to administrators.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.