Description
Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
Published: 2026-07-27
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated SQL injection affecting WordPress AWP Classifieds plugin versions up to 4.4.7. An attacker can inject malicious SQL through unvalidated input, potentially reading, modifying, or deleting data and escalating privileges. The impact includes unauthorized data access, data integrity loss, and possible system compromise. The weakness is a classic input validation failure (CWE‑89).

Affected Systems

The affected product is the Strategy11 Team's AWP Classifieds WordPress plugin, version 4.4.7 and earlier. WordPress sites using this plugin without an updated version are vulnerable.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity. EPSS score is < 1%, indicating a very low probability of exploitation in the general threat landscape. Nonetheless, the vulnerability lacks an authentication requirement and can potentially allow attackers to read, modify, or delete data. It is not listed in the CISA KEV catalog. While the EPSS score suggests limited exploitation likelihood, organizations using the affected plugin should still treat it as a high‑risk issue and apply the vendor patch promptly.

Generated by OpenCVE AI on August 3, 2026 at 17:34 UTC.

Remediation

Vendor Solution

Update the WordPress AWP Classifieds Plugin to the latest available version (at least 4.4.8).


OpenCVE Recommended Actions

  • Update the AWP Classifieds plugin to version 4.4.8 or later to remove the vulnerable code.
  • If an update is not feasible immediately, disable or remove the plugin until the update can be applied.
  • Implement input sanitization or a web application firewall to block malformed SQL payloads.
  • Monitor database activity and web logs for signs of injection attempts.

Generated by OpenCVE AI on August 3, 2026 at 17:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Strategy11
Strategy11 awp Classifieds
Wordpress
Wordpress wordpress
Vendors & Products Strategy11
Strategy11 awp Classifieds
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
Title WordPress AWP Classifieds plugin <= 4.4.7 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Strategy11 Awp Classifieds
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T18:11:52.196Z

Reserved: 2026-07-05T21:27:56.024Z

Link: CVE-2026-59550

cve-icon Vulnrichment

Updated: 2026-07-27T18:11:47.781Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:05.090

Modified: 2026-07-27T19:17:18.660

Link: CVE-2026-59550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:45:03Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')