<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WPAdverts - Classifieds Plugin - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/wpadverts---classifieds-plugin/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 18 Aug 2026 04:52:50 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/wpadverts---classifieds-plugin/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass Vulnerability in WPAdverts Classifieds Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-08-wpadverts-auth-bypass/</link><pubDate>Tue, 18 Aug 2026 04:52:50 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-wpadverts-auth-bypass/</guid><description>The WPAdverts - Classifieds Plugin for WordPress up to version 2.3.2 is vulnerable to an authorization bypass allowing unauthenticated attackers to exfiltrate internal configuration data via the REST API.</description><content:encoded><![CDATA[<p>The WPAdverts - Classifieds Plugin for WordPress, versions up to and including 2.3.2, contains an authorization bypass vulnerability identified as CVE-2026-11801. This flaw stems from a failure in the plugin to properly verify user permissions before executing actions within the classifieds-types REST API endpoint. As a result, an unauthenticated attacker can query the endpoint to retrieve internal site configuration metadata. This exfiltrated information includes registered post types, labels, associated taxonomies, form scheme metadata, contact options, and custom field meta keys. Such information disclosure facilitates reconnaissance, allowing attackers to better understand the target environment's structure for subsequent exploitation or targeted attacks against specific forms and data structures.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to harvest internal WordPress site configuration data. This reconnaissance data provides an attacker with deep insight into the site's data architecture, which is a critical precursor to identifying further vulnerabilities in custom forms or taxonomy-based operations.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the WPAdverts - Classifieds Plugin to the latest available version (beyond 2.3.2) immediately to patch the authorization logic in the classifieds-types endpoint.</li>
<li>Monitor web server access logs for anomalous, high-frequency requests originating from unauthenticated sources to REST API endpoints associated with the wp-adverts plugin.</li>
<li>Implement request rate limiting on the REST API for endpoints associated with the plugin to prevent automated scraping of configuration metadata.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>vulnerability</category><category>information-disclosure</category></item></channel></rss>