CVE-2026-14183: Unknown Classified Listing

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order.

Affected products

  • Unknown Classified Listing: before 5.3.9 (fixed in 5.3.9)

Published 2026-07-21. Last modified 2026-07-21.