CVE-2026-19074: Advanced Classifieds & Directory Pro < 3.4.3 - Unauthenticated Non-Public Listing Custom Field Disclosure
The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticated sensitive information exposure via the AJAX action acadppubliccustomfieldslistings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19074?
The severity of CVE-2026-19074 is rated at 45, indicating a moderate risk associated with the vulnerability.
How do I fix CVE-2026-19074?
To mitigate CVE-2026-19074, upgrade the Advanced Classifieds & Directory Pro plugin to version 3.4.3 or later.
What type of information is exposed in CVE-2026-19074?
CVE-2026-19074 exposes non-public listing custom field data, which could contain sensitive information.
Is authentication required to exploit CVE-2026-19074?
No, CVE-2026-19074 can be exploited by unauthenticated users, making it a significant risk.
What systems are affected by CVE-2026-19074?
CVE-2026-19074 affects versions of the Advanced Classifieds & Directory Pro WordPress plugin prior to 3.4.3.