Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 21 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 | |
| Metrics |
cvssV3_1
|
Tue, 21 Jul 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order. | |
| Title | Classified Listing < 5.3.9 - Subscriber+ Payment Receipt Disclosure via IDOR | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-21T15:23:43.105Z
Reserved: 2026-06-30T08:11:18.256Z
Link: CVE-2026-14183
Updated: 2026-07-21T15:22:15.496Z
Status : Deferred
Published: 2026-07-21T07:16:34.020
Modified: 2026-07-21T18:51:56.150
Link: CVE-2026-14183
No data.
OpenCVE Enrichment
Updated: 2026-07-30T18:15:13Z