CVE-2026-42679: WordPress Classified Listing plugin <= 5.3.8 - Arbitrary File Download vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal.
This issue affects Classified Listing: from n/a through 5.3.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Classified Listing Pluginto a version that resolves this vulnerability.Fixed in 5.3.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42679?
The severity of CVE-2026-42679 is medium, rated at 6.5.
How do I fix CVE-2026-42679?
To fix CVE-2026-42679, update the WordPress Classified Listing Plugin to at least version 5.3.9.
What is the exploit type associated with CVE-2026-42679?
CVE-2026-42679 is associated with a Path Traversal exploit that allows arbitrary file downloads.
Which versions of the Classified Listing Plugin are affected by CVE-2026-42679?
CVE-2026-42679 affects all versions of the Classified Listing Plugin from n/a through 5.3.8.
What should I do if I cannot update the Classified Listing Plugin for CVE-2026-42679?
If you cannot update the plugin, consider disabling it or adding additional security measures to protect your site.