Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-19074— Advanced Classifieds & Directory Pro < 3.4.3 - Unauthenticated Non-Public Listing Custom Field Disclosure

AI Predicted 5.3 Difficulty: Easy

Possible ATT&CK Techniques 1AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-19074

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Advanced Classifieds & Directory Pro < 3.4.3 - Unauthenticated Non-Public Listing Custom Field Disclosure
Source: CVE Program / CVE List V5
Vulnerability Description
The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticated sensitive information exposure via the AJAX action `acadp_public_custom_fields_listings`.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
UnknownAdvanced Classifieds & Directory Pro 0 ~ 3.4.3 -

II. Public POCs for CVE-2026-19074

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19074

登录查看更多情报信息。

Vendor Advisories for CVE-2026-19074 (1)

Same Patch Batch · Unknown · 2026-08-10 · 48 CVEs total

CVE-2026-17010Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta
CVE-2026-16299Single Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password Reset
CVE-2026-18468Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Verif
CVE-2026-16298FoodBoxBooker < 1.0.7 - Unauthenticated Arbitrary Password Reset
CVE-2026-18030Bricksforge < 3.1.8.8 - Unauthenticated Arbitrary Password Reset via Pro Forms
CVE-2026-17541Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure
CVE-2026-17542Bit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_fm_connector
CVE-2026-17540Bit File Manager < 6.9.1 - Subscriber+ Arbitrary File Read and Deletion via Connector Comm
CVE-2026-16257Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret T
CVE-2026-17016Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Underpayment
CVE-2026-17012Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver
CVE-2026-18666Library Management System < 3.6.7 - Subscriber+ SQL Injection via Filter Value
CVE-2026-17018CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclosure via IDOR
CVE-2026-12971LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_featur
CVE-2026-13600AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync Cron
CVE-2026-13170Eventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting
CVE-2026-13701Advanced Excerpt < 4.5 - Admin+ Stored XSS via Ellipsis Setting
CVE-2026-14206HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure
CVE-2026-14860Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery
CVE-2026-14941Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multipl

Showing top 20 of 48 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-19074

No comments yet


Leave a comment