CVE-2026-94665: WordPress Classified Listing plugin <= 6.1.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mamunur Rashid Classified Listing classified-listing allows Stored XSS.This issue affects Classified Listing: from n/a through 6.1.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Classified Listingto a version that resolves this vulnerability.Fixed in 6.1.3
Event History
Frequently Asked Questions
What access and conditions are required for exploitation?
The vector is network-accessible, exploitation complexity is low, and the attacker needs low-level privileges. Exploitation also requires user interaction.
What impact could successful exploitation have?
The vulnerability is a stored XSS issue with low confidentiality, integrity, and availability impact. The reported scope is changed, indicating the impact may extend beyond the vulnerable component's security authority.