AWP Classifieds <= 4.4.7 - Unauthenticated SQL Injection
high
The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.4.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries...
- CVSS:
- 7.5
- Affected:
- up to 4.4.7
- Fixed in:
- 4.4.8
- Disclosed:
- Jul 23, 2026
CVE-2026-59550 on NVD →
AWP Classifieds <= 4.4.7 - Missing Authorization
medium
The AWP Classifieds plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.4.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.4.7
- Fixed in:
- 4.4.8
- Disclosed:
- Jul 22, 2026
CVE-2026-65469 on NVD →
AWP Classifieds <= 4.4.5 - Missing Authorization
medium
The AWP Classifieds plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.4.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.4.5
- Fixed in:
- 4.4.6
- Disclosed:
- May 12, 2026
CVE-2026-42726 on NVD →
AWP Classifieds <= 4.4.6 - Unauthenticated SQL Injection via 'regions'
high
The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated atta...
- CVSS:
- 7.5
- Affected:
- up to 4.4.6
- Fixed in:
- 4.4.6.1
- Disclosed:
- May 4, 2026
CVE-2026-5100 on NVD →
AWP Classifieds <= 4.4.4 - Missing Authorization
high
The AWP Classifieds plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.4.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 7.5
- Affected:
- up to 4.4.4
- Fixed in:
- 4.4.5
- Disclosed:
- Apr 8, 2026
CVE-2026-39533 on NVD →
AWP Classifieds [another-wordpress-classifieds-plugin] <= 4.4.3 (unfixed)
unknown
[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Retrieve Embedded Sensitive Data.This issue affects AWP Classifieds: from n/a through <= 4.4.3.
- Affected:
- up to 4.4.3
- Fix:
- No patched version reported
- Disclosed:
- Jan 23, 2026
CVE-2026-24593 on NVD →
AWP Classifieds <= 4.4.3 - Unauthenticated Information Exposure
medium
The AWP Classifieds plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.4
- Disclosed:
- Jan 16, 2026
CVE-2026-24593 on NVD →
AWP Classifieds <= 4.4.3 - Unauthenticated Arbitrary Shortcode Execution
medium
The The WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_sho...
- CVSS:
- 6.5
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.4
- Disclosed:
- Sep 22, 2025
CVE-2025-57928 on NVD →
AWP Classifieds [another-wordpress-classifieds-plugin] < 4.3.2
unknown
[en] Missing Authorization vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1.
- Affected:
- up to 4.3.2
- Fixed in:
- 4.3.2
- Disclosed:
- Jun 9, 2024
CVE-2024-31350 on NVD →
AWP Classifieds [another-wordpress-classifieds-plugin] < 4.3.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1.
- Affected:
- up to 4.3.2
- Fixed in:
- 4.3.2
- Disclosed:
- Apr 15, 2024
CVE-2024-32447 on NVD →
AWP Classifieds <= 4.3.1 - Cross-Site Request Forgery
medium
The AWP Classifieds plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.1. This is due to missing or incorrect nonce validation on the ajax() function. This makes it possible for unauthenticated attackers to edit balances via a forged request granted they can trick a s...
- CVSS:
- 4.3
- Affected:
- up to 4.3.1
- Fixed in:
- 4.3.2
- Disclosed:
- Apr 12, 2024
CVE-2024-32447 on NVD →
AWP Classifieds <= 4.3.1 - Missing Authorization
medium
The AWP Classifieds plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.3.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 4.3.1
- Fixed in:
- 4.3.2
- Disclosed:
- Apr 5, 2024
CVE-2024-31350 on NVD →
AWP Classifieds [another-wordpress-classifieds-plugin] < 4.3.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugin <= 4.3 versions.
- Affected:
- up to 4.3.1
- Fixed in:
- 4.3.1
- Disclosed:
- Oct 6, 2023
CVE-2023-41801 on NVD →
AWP Classifieds <= 4.3 - Cross-Site Request Forgery
medium
The AWP Classifieds plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3. This is due to missing nonce validation on several functions such as dispatch(), try_to_delete_categories(), try_to_update_category(), try_to_move_categories(), and more. This makes it possible fo...
- CVSS:
- 4.3
- Affected:
- up to 4.3
- Fixed in:
- 4.3.1
- Disclosed:
- Sep 5, 2023
CVE-2023-41801 on NVD →
AWP Classifieds [another-wordpress-classifieds-plugin] < 2.0
unknown
Upgrade the plugin.
An unknown person discovered and reported this Arbitrary File Upload vulnerability in WordPress AWP Classifieds Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulne...
- Affected:
- up to 2.0
- Fixed in:
- 2.0
- Disclosed:
- May 15, 2023
AWP Classifieds [another-wordpress-classifieds-plugin] < 4.3
unknown
[en] The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection
- Affected:
- up to 4.3
- Fixed in:
- 4.3
- Disclosed:
- Oct 31, 2022
CVE-2022-3254 on NVD →
AWP Classifieds <= 4.2.1 - Unauthenticated SQL Injection
critical
The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 4.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to appen...
- CVSS:
- 9.8
- Affected:
- up to 4.2.1
- Fixed in:
- 4.3
- Disclosed:
- Oct 10, 2022
CVE-2022-3254 on NVD →
AWP Classifieds [another-wordpress-classifieds-plugin] < 2.0
unknown
This plugin is prone to an unspecified vulnerability.
Upgrade the plugin.
- Affected:
- up to 2.0
- Fixed in:
- 2.0
- Disclosed:
- May 15, 2015
AWP Classifieds [another-wordpress-classifieds-plugin] < 4.0
unknown
[en] Cross-site scripting (XSS) vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.
- Affected:
- up to 4.0
- Fixed in:
- 4.0
- Disclosed:
- Jan 13, 2015
CVE-2014-10012 on NVD →
AWP Classifieds [another-wordpress-classifieds-plugin] < 4.0
unknown
[en] SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action.
- Affected:
- up to 4.0
- Fixed in:
- 4.0
- Disclosed:
- Jan 13, 2015
CVE-2014-10013 on NVD →
WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds <= 3.3.1 - Cross-Site Scripting
medium
The WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error_message’ parameter in versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthentica...
- CVSS:
- 6.1
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.2
- Disclosed:
- Dec 9, 2014
AWP Classifieds [another-wordpress-classifieds-plugin] < 3.3.2
unknown
The WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error_message’ parameter in versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthentica...
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.2
- Disclosed:
- Dec 9, 2014
WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds < 3.0 - SQL Injection
medium
SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action.
- CVSS:
- 6.3
- Affected:
- up to 3.0
- Fixed in:
- 3.0
- Disclosed:
- Nov 10, 2014
CVE-2014-10013 on NVD →
WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds < 3.0 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.
- CVSS:
- 6.1
- Affected:
- up to 3.0
- Fixed in:
- 3.0
- Disclosed:
- Nov 8, 2014
CVE-2014-10012 on NVD →
AWP Classifieds [another-wordpress-classifieds-plugin] < 2.0
unknown
[en] Unspecified vulnerability in the Another WordPress Classifieds Plugin before 2.0 for WordPress has unknown impact and attack vectors related to "image uploads."
- Affected:
- up to 2.0
- Fixed in:
- 2.0
- Disclosed:
- Sep 6, 2012
CVE-2012-4874 on NVD →
WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds < 2.0 - Arbitrary File Upload
high
The WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the admin_handleimagesupload function in versions up to, and including, 1.8.9.4. This makes it possible for authenticated attackers, with admi...
- CVSS:
- 7.2
- Affected:
- up to 2.0
- Fixed in:
- 2.0
- Disclosed:
- Apr 3, 2012
CVE-2012-4874 on NVD →
AWP Classifieds [another-wordpress-classifieds-plugin] <= 4.3.5 (unfixed)
unknown
- Affected:
- up to 4.3.5
- Fix:
- No patched version reported
CVE-2025-57928 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database