CVE-2026-11801

WPAdverts <= 2.3.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via classifieds-types REST Endpoint

The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve internal site configuration data exposed by the classifieds-types REST endpoint, including registered post types, labels, associated taxonomies, form scheme metadata, contact options, and custom field meta keys.


We have discovered 230 live websites that are affected by CVE-2026-11801.

Run a Free Instant Scan




Affected Software

Product  Wpadverts
Category Wordpress Plugins
Vulnerable Domains230 live websites (63% of Wpadverts install base)
Vulnerable Versions
  • from 0 through 2.3.2
Vulnerable Versions Count8 versions ( 89% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Aug 18, 2026
  • Updated - Aug 18, 2026

Credits

  • Deva Parekh (finder)

Website Distribution by Country

Number of websites using CVE-2026-11801
United States64 websites



Poland36 websites
Germany24 websites
France19 websites
GB13 websites
Hungary10 websites
Russia7 websites
Chile6 websites
Italy6 websites
Australia5 websites

Website Distribution by TLD

Number of websites using CVE-2026-11801
.com72 websites
.pl29 websites
.de16 websites
.org12 websites
.fr9 websites
.net8 websites
.ru7 websites
.co.uk7 websites
.com.au4 websites
.it3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-11801

Top websites that are affected by CVE-2026-11801. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**.org United States***,***
*************.ie Ireland***,***
******.**.ee Estonia***,***
********.org United States***,***
******.de Germany***,***
************.hu Hungary***,***
*****.**.nz United States***,***
******.**.uk GB*,***,***
*****.by Belarus*,***,***
*******.ru Russia*,***,***
See full domain list

FAQ

CVE-2026-11801 is Missing Authorization in Wpadverts
A total of 230 websites have been identified as vulnerable to CVE-2026-11801, based on global website indexing conducted by WebTechSurvey.
The Wpadverts is affected by the CVE-2026-11801 vulnerability.
Wpadverts versions up to and including 2.3.2 are vulnerable to CVE-2026-11801.