Impact
The vulnerability is an unauthenticated SQL injection affecting WordPress AWP Classifieds plugin versions up to 4.4.7. An attacker can inject malicious SQL through unvalidated input, potentially reading, modifying, or deleting data and escalating privileges. The impact includes unauthorized data access, data integrity loss, and possible system compromise. The weakness is a classic input validation failure (CWE‑89).
Affected Systems
The affected product is the Strategy11 Team's AWP Classifieds WordPress plugin, version 4.4.7 and earlier. WordPress sites using this plugin without an updated version are vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. EPSS score is < 1%, indicating a very low probability of exploitation in the general threat landscape. Nonetheless, the vulnerability lacks an authentication requirement and can potentially allow attackers to read, modify, or delete data. It is not listed in the CISA KEV catalog. While the EPSS score suggests limited exploitation likelihood, organizations using the affected plugin should still treat it as a high‑risk issue and apply the vendor patch promptly.
OpenCVE Enrichment