WordPress security by component
AWP Classifieds
Plugin description
AWP Classifieds creates classified listings with categories, search, submission forms, and management tools in WordPress.
AWP Classifieds (another-wordpress-classifieds-plugin) is a WordPress plugin with 11 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest published CVSS base score is 10.
Plugin slug:
another-wordpress-classifieds-pluginLatest vulnerability
CVE-2026-59550: AWP Classifieds permits unauthenticated SQL injection
AWP Classifieds through 4.4.7 lets an unauthenticated attacker supply input that reaches an SQL statement without safe parameterization. Exploitation can interact with the WordPress database and potentially read or alter data available to the database user.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-59550
AWP Classifieds permits unauthenticated SQL injection
AWP Classifieds through 4.4.7 lets an unauthenticated attacker supply input that reaches an SQL statement without safe parameterization. Exploitation can interact with the WordPress database and potentially read or alter data available to the database user.
|
4.4.8 |
CVE9.3
NVDPending
|
| Jul 23, 2026 |
CVE-2026-65469
AWP Classifieds: Broken access control
AWP Classifieds is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 4.4.7.
|
4.4.8 |
CVE5.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-39533
AWP Classifieds: Broken access control
AWP Classifieds is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 4.4.4.
|
4.4.5 |
CVE7.5
NVDPending
|
| May 27, 2026 |
CVE-2026-42726
AWP Classifieds: A security weakness
AWP Classifieds is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.4.5.
|
4.4.6 |
CVE6.5
NVDPending
|
| May 05, 2026 |
CVE-2026-5100
AWP Classifieds: SQL injection
AWP Classifieds is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 4.4.5.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jan 23, 2026 |
CVE-2026-24593
AWP Classifieds: A security weakness
AWP Classifieds is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 22, 2025 |
CVE-2025-57928
AWP Classifieds: Cross-site scripting
AWP Classifieds is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jun 09, 2024 |
CVE-2024-31350
AWP Classifieds: A security weakness
AWP Classifieds is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Apr 15, 2024 |
CVE-2024-32447
AWP Classifieds: Cross-site request forgery
AWP Classifieds is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 06, 2023 |
CVE-2023-41801
Another Wordpress Classifieds Plugin: Cross-site request forgery
Another Wordpress Classifieds Plugin is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Sep 06, 2012 |
CVE-2012-4874
Another Wordpress Classifieds Plugin: A security weakness
Another Wordpress Classifieds Plugin is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD10.0
|