CVE-2025-1063

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.4 via the rtcl_taxonomy_settings_export function. This makes it possible for unauthenticated attackers to extract sensitive data including API keys and tokens.
Configurations

Configuration 1 (hide)

cpe:2.3:a:radiustheme:classified_listing:*:*:*:*:-:wordpress:*:*

History

17 Jun 2026, 08:38

Type Values Removed Values Added
First Time Radiustheme
Radiustheme classified Listing
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:radiustheme:classified_listing:*:*:*:*:-:wordpress:*:*
Summary
  • (es) El complemento Classified Listing – Classified ads & Business Directory Plugin para WordPress es vulnerable a la exposición de información confidencial en todas las versiones hasta la 4.0.4 incluida a través de la función rtcl_taxonomy_settings_export. Esto permite que atacantes no autenticados extraigan datos confidenciales, incluidas claves API y tokens.
References () https://plugins.trac.wordpress.org/changeset/3241883/classified-listing - () https://plugins.trac.wordpress.org/changeset/3241883/classified-listing - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/e701b771-59f2-4783-b0a1-bea4d6c3d245?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/e701b771-59f2-4783-b0a1-bea4d6c3d245?source=cve - Third Party Advisory

25 Feb 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-25 07:15

Updated : 2026-06-17 08:38


NVD link : CVE-2025-1063

Mitre link : CVE-2025-1063

CVE.ORG link : CVE-2025-1063


JSON object : View

Products Affected

radiustheme

  • classified_listing
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo