CVE detail
CVE-2026-11801
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve internal site configuration data exposed by the classifieds-types REST endpoint, including registered post types, labels, associated taxonomies, form scheme metadata, contact options, and custom field meta keys.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 5
- within the 30d window
- Peak daily
- 5
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- https://www.wordfence.com/threat-intel/vulnerabilities/id/37bb8d68-dd87-437a-80e5-e99e93dc55b6?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comAug 18, 2026, 3:16 AM - https://plugins.trac.wordpress.org/changeset?reponame=&new=3635095%40wpadverts%2Ftrunk&old=3557928%40wpadverts%2Ftrunkplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 18, 2026, 3:16 AM - https://plugins.trac.wordpress.org/browser/wpadverts/tags/2.3.3/includes/class-rest-blocks.php#L49plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 18, 2026, 3:16 AM - https://plugins.trac.wordpress.org/browser/wpadverts/tags/2.3.2/includes/class-rest-blocks.php#L50plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 18, 2026, 3:16 AM - https://plugins.trac.wordpress.org/browser/wpadverts/tags/2.3.2/includes/class-rest-blocks.php#L13plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 18, 2026, 3:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-66589CVSS 5.4 · Medium
Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B2BKing: from n/a through…
- CVE-2026-53453CVSS 8.7 · High
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any a…
- CVE-2026-12631CVSS 6.5 · Medium
The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscall in include/zephyr/kernel.h) through thread_obj_validate() in kernel/thread.c.…
- CVE-2026-76032CVSS 5.3 · Medium
Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/link/{Uuid} in idm/share/rest/handler.go reads the workspac…
- CVE-2026-71322CVSS 4.3 · Medium
Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePermission ownership check inside the plugin.requires_key branch for POST /api/1/ce…
- CVE-2026-71317CVSS 6.5 · Medium
Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require AuthorityPermission on the parent authority when ADMIN_ONLY_AUTHORI…