The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 | |
| Metrics |
cvssV3_1
|
Tue, 21 Jul 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order. | |
| Title | Classified Listing < 5.3.9 - Subscriber+ Payment Receipt Disclosure via IDOR | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-21T15:23:43.105Z
Reserved: 2026-06-30T08:11:18.256Z
Link: CVE-2026-14183
Updated: 2026-07-21T15:22:15.496Z
No data.
No data.
OpenCVE Enrichment
No data.