CVE-2026-11801
7.5WordPress · WPAdverts – Classifieds Plugin
The WPAdverts plugin for WordPress contains an authorization bypass vulnerability allowing unauthorized information disclosure.
Executive summary
An authorization bypass vulnerability in the WPAdverts plugin for WordPress allows unauthenticated attackers to access sensitive restricted data.
Vulnerability
The plugin fails to perform adequate capability checks, leading to a missing authorization vulnerability that allows unauthenticated users to access restricted REST API blocks.
Business impact
This vulnerability enables unauthorized parties to retrieve sensitive data, potentially leading to information leakage and a compromise of user privacy. With a CVSS score of 7.5, the risk to data confidentiality is significant for any organization relying on this plugin for classifieds management.
Remediation
Immediate Action: Update the WPAdverts – Classifieds Plugin to version 2.3.3 or later immediately to resolve the authorization logic flaw.
Proactive Monitoring: Review server logs for anomalous REST API requests or unauthorized access patterns targeting the plugin endpoints.
Compensating Controls: If an immediate update is not possible, disable the plugin to prevent exploitation until the patch is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Administrators must verify their current plugin version and perform the update to 2.3.3 immediately. Failure to address this vulnerability increases the risk of unauthorized data access significantly.