{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wpadverts---classifieds-plugin/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-11801"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WPAdverts - Classifieds Plugin"],"_cs_severities":["high"],"_cs_tags":["wordpress","vulnerability","information-disclosure"],"_cs_type":"advisory","_cs_vendors":["WPAdverts"],"content_html":"\u003cp\u003eThe WPAdverts - Classifieds Plugin for WordPress, versions up to and including 2.3.2, contains an authorization bypass vulnerability identified as CVE-2026-11801. This flaw stems from a failure in the plugin to properly verify user permissions before executing actions within the classifieds-types REST API endpoint. As a result, an unauthenticated attacker can query the endpoint to retrieve internal site configuration metadata. This exfiltrated information includes registered post types, labels, associated taxonomies, form scheme metadata, contact options, and custom field meta keys. Such information disclosure facilitates reconnaissance, allowing attackers to better understand the target environment's structure for subsequent exploitation or targeted attacks against specific forms and data structures.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to harvest internal WordPress site configuration data. This reconnaissance data provides an attacker with deep insight into the site's data architecture, which is a critical precursor to identifying further vulnerabilities in custom forms or taxonomy-based operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the WPAdverts - Classifieds Plugin to the latest available version (beyond 2.3.2) immediately to patch the authorization logic in the classifieds-types endpoint.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous, high-frequency requests originating from unauthenticated sources to REST API endpoints associated with the wp-adverts plugin.\u003c/li\u003e\n\u003cli\u003eImplement request rate limiting on the REST API for endpoints associated with the plugin to prevent automated scraping of configuration metadata.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T04:52:50Z","date_published":"2026-08-18T04:52:50Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wpadverts-auth-bypass/","summary":"The WPAdverts - Classifieds Plugin for WordPress up to version 2.3.2 is vulnerable to an authorization bypass allowing unauthenticated attackers to exfiltrate internal configuration data via the REST API.","title":"Authorization Bypass Vulnerability in WPAdverts Classifieds Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-wpadverts-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - WPAdverts - Classifieds Plugin","version":"https://jsonfeed.org/version/1.1"}