What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Classified Listing classified-listing allows PHP Local File Inclusion.This issue affects Classified Listing: from n/a through <= 3.1.16.
Explanation of Vulnerability in Simple Terms
02Summary
Classified Listing versions up to 3.1.16 contain an information disclosure vulnerability. An attacker with low-level site access can read sensitive data that should be restricted. The vulnerability requires specific conditions to exploit and does not allow data modification or system disruption.
What an attacker can do
03Attacker Capabilities
Read sensitive information they should not have access to.
Potential impact on your site
04Site Impact
User data or configuration details may be exposed to authenticated attackers with basic permissions.
Conditions required to exploit
05Prerequisites
Low-level user account on the site; no user interaction required.
Key dates
06Disclosure timeline
November 16, 2024
CVE published
April 28, 2026
Record updated