CyberRota Analysis
AI-GeneratedThe Classified Listing WordPress plugin versions prior to 5.4.4 are vulnerable due to a lack of capability checks on an AJAX action, which permits users with contributor-level access and higher to access sensitive daily revenue figures typically restricted to administrators and report managers. This exposure could lead to unauthorized disclosure of financial information, potentially impacting the integrity of business operations. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read daily revenue figures normally restricted to administrators and report managers.