S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Misconfiguration·Updated Aug 30, 2026

CVE-2026-11801 Scanner

CVE-2026-11801 Scanner - Information Disclosure vulnerability in WPAdverts

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-11801
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve internal site configuration data exposed by the classifieds-types REST endpoint, including registered post types, labels, associated taxonomies, form scheme metadata, contact options, and custom field meta keys.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WPAdverts – Classifieds Pluginby gwin
0
Updated Sep 9, 2026View on NVD →
Detail

WPAdverts is a highly flexible classifieds plugin designed for WordPress. Used by site owners for creating and managing classified ads, WPAdverts caters to both small and large businesses. Its deployment is widespread, found in numerous sites dealing with ad postings. Many webmasters value its robust and user-friendly interface. The software is crucial for users dedicated to building and maintaining ad-driven content. WPAdverts continuously updates its functionalities to address diverse user needs.

The vulnerability in WPAdverts is an Information Disclosure issue. It involves unauthorized access resulting from improper user authorization verification within the REST endpoint. Exploitation of this vulnerability allows unauthenticated attackers to retrieve sensitive site configuration data. This vulnerability requires no user authentication to exploit. The issue highlights significant gaps in authorization checks.

The affected endpoint is the "classifieds-types" REST endpoint, which improperly verifies user authorization. It becomes accessible to unauthorized users due to the lack of stringent controls. Attackers can exploit this endpoint to access internal site configuration data. Ensuring proper authorization checks in endpoints prevents such exposure. The vulnerability is highly critical given unrestricted access it grants.

Exploitation of this vulnerability can lead to serious consequences. Malicious actors may access sensitive configuration data about the site. Unauthorized disclosure can further expose other vulnerabilities or weaknesses. This can lead to potential security breaches or unauthorized site control access. Sensitive data disclosure may cause reputation damage and financial loss for the site operator.

REFERENCES

Solution Advice
  • Upgrade WPAdverts to a version above 2.3.2 to ensure security patches are applied.
  • Implement strict authorization checks on all REST API endpoints.
  • Review and restrict REST API access to only authorized users.
  • Conduct regular audits and security assessments to identify potential vulnerabilities.
  • Enable logging and monitoring to detect unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2026-11801 Scanner - Information Disclosure vulnerability in WPAdverts | S4E