4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Description
The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the "rtcl_ajax_add_listing_type", "rtcl_ajax_update_listing_type", and "rtcl_ajax_delete_listing_type" function in all versions up to, and including, 5.2.0. This makes it possible for authenticated attackers, with subscriber level access and above, to add, update, or delete listing types.
Basic Information
ID
CVE-2025-12953
Source
Wordfence
Published
Nov 11, 2025 at 11:03
Affected Product
Vendor
techlabpro1
Product
Classified Listing – AI-Powered Classified ads & Business Directory Plugin
Version
*
Affected Versions
techlabpro1 Classified Listing – AI-Powered Classified ads & Business Directory Plugin *