SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16276

LOW · CVSS 2.7 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The Classified Listing WordPress plugin versions prior to 5.4.4 are vulnerable due to a lack of capability checks on an AJAX action, which permits users with contributor-level access and higher to access sensitive daily revenue figures typically restricted to administrators and report managers. This exposure could lead to unauthorized disclosure of financial information, potentially impacting the integrity of business operations. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-16276
Severity
LOW
CVSS
2.7
EPSS
0.18%
WordPress

Original NVD Description

The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read daily revenue figures normally restricted to administrators and report managers.