PT-2025-46325 · WordPress · The Classified Listing – Classified Ads & Business Directory Plugin

Rafshanzani Suhada

·

Published

2025-11-11

·

Updated

2025-11-11

·

CVE-2025-12953

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Classified Listing – AI-Powered Classified ads & Business Directory Plugin versions up to and including 5.2.0
Description The Classified Listing – AI-Powered Classified ads & Business Directory Plugin for WordPress is susceptible to unauthorized data modification. A missing capability check within the rtcl ajax add listing type, rtcl ajax update listing type, and rtcl ajax delete listing type functions allows authenticated attackers with subscriber-level access or higher to add, update, or delete listing types.
Recommendations Update The Classified Listing – AI-Powered Classified ads & Business Directory Plugin to a version later than 5.2.0.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-12953

Affected Products

The Classified Listing – Classified Ads & Business Directory Plugin