Impact
The AWP Classifieds plugin suffers from an unauthenticated broken access control flaw (CWE-862). An attacker who can reach the plugin’s administrative interfaces can bypass authorization checks and access or modify data that should be restricted. This can result in exposure of private classified listings, tampering with existing entries, or even deletion of data, thereby compromising confidentiality, integrity, and potentially availability if abused.
Affected Systems
The vulnerability affects the AWP Classifieds plugin from WPTasty running on WordPress. Versions 4.4.4 and earlier are impacted; updating to 4.4.5 or later mitigates the issue.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1% suggests that exploitation is statistically rare at present. It is not listed in the CISA KEV catalog. Because the flaw allows unauthenticated users to trigger the vulnerability via web requests, the likely attack vector is a remote Web application attack. Attackers would need to identify the plugin’s endpoints and send crafted requests. The risk is moderate to high if an attacker is able to exploit the weakness, but low probability of widespread exploitation due to low EPSS.
OpenCVE Enrichment