plugin

Another Wordpress Classifieds Plugin Vulnerabilities

27 known security issues reported for the Another Wordpress Classifieds Plugin WordPress plugin. Most recent disclosed Jul 23, 2026.

1 critical 4 high 10 medium

Running Another Wordpress Classifieds Plugin on your site? Check whether your installed version is affected.

Scan your site free

AWP Classifieds <= 4.4.7 - Unauthenticated SQL Injection

high

The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.4.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries...

CVSS:
7.5
Affected:
up to 4.4.7
Fixed in:
4.4.8
Disclosed:
Jul 23, 2026

CVE-2026-59550 on NVD →

AWP Classifieds <= 4.4.7 - Missing Authorization

medium

The AWP Classifieds plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.4.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.4.7
Fixed in:
4.4.8
Disclosed:
Jul 22, 2026

CVE-2026-65469 on NVD →

AWP Classifieds <= 4.4.5 - Missing Authorization

medium

The AWP Classifieds plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.4.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.4.5
Fixed in:
4.4.6
Disclosed:
May 12, 2026

CVE-2026-42726 on NVD →

AWP Classifieds <= 4.4.6 - Unauthenticated SQL Injection via 'regions'

high

The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated atta...

CVSS:
7.5
Affected:
up to 4.4.6
Fixed in:
4.4.6.1
Disclosed:
May 4, 2026

CVE-2026-5100 on NVD →

AWP Classifieds <= 4.4.4 - Missing Authorization

high

The AWP Classifieds plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.4.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
7.5
Affected:
up to 4.4.4
Fixed in:
4.4.5
Disclosed:
Apr 8, 2026

CVE-2026-39533 on NVD →

AWP Classifieds [another-wordpress-classifieds-plugin] <= 4.4.3 (unfixed)

unknown

[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Retrieve Embedded Sensitive Data.This issue affects AWP Classifieds: from n/a through <= 4.4.3.

Affected:
up to 4.4.3
Fix:
No patched version reported
Disclosed:
Jan 23, 2026

CVE-2026-24593 on NVD →

AWP Classifieds <= 4.4.3 - Unauthenticated Information Exposure

medium

The AWP Classifieds plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 4.4.3
Fixed in:
4.4.4
Disclosed:
Jan 16, 2026

CVE-2026-24593 on NVD →

AWP Classifieds <= 4.4.3 - Unauthenticated Arbitrary Shortcode Execution

medium

The The WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_sho...

CVSS:
6.5
Affected:
up to 4.4.3
Fixed in:
4.4.4
Disclosed:
Sep 22, 2025

CVE-2025-57928 on NVD →

AWP Classifieds [another-wordpress-classifieds-plugin] < 4.3.2

unknown

[en] Missing Authorization vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1.

Affected:
up to 4.3.2
Fixed in:
4.3.2
Disclosed:
Jun 9, 2024

CVE-2024-31350 on NVD →

AWP Classifieds [another-wordpress-classifieds-plugin] < 4.3.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1.

Affected:
up to 4.3.2
Fixed in:
4.3.2
Disclosed:
Apr 15, 2024

CVE-2024-32447 on NVD →

AWP Classifieds <= 4.3.1 - Cross-Site Request Forgery

medium

The AWP Classifieds plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.1. This is due to missing or incorrect nonce validation on the ajax() function. This makes it possible for unauthenticated attackers to edit balances via a forged request granted they can trick a s...

CVSS:
4.3
Affected:
up to 4.3.1
Fixed in:
4.3.2
Disclosed:
Apr 12, 2024

CVE-2024-32447 on NVD →

AWP Classifieds <= 4.3.1 - Missing Authorization

medium

The AWP Classifieds plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.3.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 4.3.1
Fixed in:
4.3.2
Disclosed:
Apr 5, 2024

CVE-2024-31350 on NVD →

AWP Classifieds [another-wordpress-classifieds-plugin] < 4.3.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugin <= 4.3 versions.

Affected:
up to 4.3.1
Fixed in:
4.3.1
Disclosed:
Oct 6, 2023

CVE-2023-41801 on NVD →

AWP Classifieds <= 4.3 - Cross-Site Request Forgery

medium

The AWP Classifieds plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3. This is due to missing nonce validation on several functions such as dispatch(), try_to_delete_categories(), try_to_update_category(), try_to_move_categories(), and more. This makes it possible fo...

CVSS:
4.3
Affected:
up to 4.3
Fixed in:
4.3.1
Disclosed:
Sep 5, 2023

CVE-2023-41801 on NVD →

AWP Classifieds [another-wordpress-classifieds-plugin] < 2.0

unknown

Upgrade the plugin. An unknown person discovered and reported this Arbitrary File Upload vulnerability in WordPress AWP Classifieds Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulne...

Affected:
up to 2.0
Fixed in:
2.0
Disclosed:
May 15, 2023

AWP Classifieds [another-wordpress-classifieds-plugin] < 4.3

unknown

[en] The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection

Affected:
up to 4.3
Fixed in:
4.3
Disclosed:
Oct 31, 2022

CVE-2022-3254 on NVD →

AWP Classifieds <= 4.2.1 - Unauthenticated SQL Injection

critical

The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 4.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to appen...

CVSS:
9.8
Affected:
up to 4.2.1
Fixed in:
4.3
Disclosed:
Oct 10, 2022

CVE-2022-3254 on NVD →

AWP Classifieds [another-wordpress-classifieds-plugin] < 2.0

unknown

This plugin is prone to an unspecified vulnerability. Upgrade the plugin.

Affected:
up to 2.0
Fixed in:
2.0
Disclosed:
May 15, 2015

AWP Classifieds [another-wordpress-classifieds-plugin] < 4.0

unknown

[en] Cross-site scripting (XSS) vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.

Affected:
up to 4.0
Fixed in:
4.0
Disclosed:
Jan 13, 2015

CVE-2014-10012 on NVD →

AWP Classifieds [another-wordpress-classifieds-plugin] < 4.0

unknown

[en] SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action.

Affected:
up to 4.0
Fixed in:
4.0
Disclosed:
Jan 13, 2015

CVE-2014-10013 on NVD →

WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds <= 3.3.1 - Cross-Site Scripting

medium

The WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error_message’ parameter in versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthentica...

CVSS:
6.1
Affected:
up to 3.3.1
Fixed in:
3.3.2
Disclosed:
Dec 9, 2014

AWP Classifieds [another-wordpress-classifieds-plugin] < 3.3.2

unknown

The WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error_message’ parameter in versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthentica...

Affected:
up to 3.3.2
Fixed in:
3.3.2
Disclosed:
Dec 9, 2014

WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds < 3.0 - SQL Injection

medium

SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action.

CVSS:
6.3
Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Nov 10, 2014

CVE-2014-10013 on NVD →

WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds < 3.0 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.

CVSS:
6.1
Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Nov 8, 2014

CVE-2014-10012 on NVD →

AWP Classifieds [another-wordpress-classifieds-plugin] < 2.0

unknown

[en] Unspecified vulnerability in the Another WordPress Classifieds Plugin before 2.0 for WordPress has unknown impact and attack vectors related to "image uploads."

Affected:
up to 2.0
Fixed in:
2.0
Disclosed:
Sep 6, 2012

CVE-2012-4874 on NVD →

WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds < 2.0 - Arbitrary File Upload

high

The WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the admin_handleimagesupload function in versions up to, and including, 1.8.9.4. This makes it possible for authenticated attackers, with admi...

CVSS:
7.2
Affected:
up to 2.0
Fixed in:
2.0
Disclosed:
Apr 3, 2012

CVE-2012-4874 on NVD →

AWP Classifieds [another-wordpress-classifieds-plugin] <= 4.3.5 (unfixed)

unknown
Affected:
up to 4.3.5
Fix:
No patched version reported

CVE-2025-57928 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database