Impact
An unauthenticated Broken Access Control flaw in the AWP Classifieds plugin for WordPress allows attackers to perform privileged actions such as adding, editing, or deleting classified listings. The vulnerability arises from missing or inadequate permission checks, classified as CWE‑862.
Affected Systems
The vulnerability affects the Strategy11 Team AWP Classifieds WordPress plugin in all releases up to and including 4.4.7. WordPress sites utilizing these versions are susceptible unless the plugin is removed, disabled, or upgraded to a patched release.
Risk and Exploitability
The CVSS score of 5.3 places the issue in the medium severity range, while an EPSS score of less than 1% indicates a very low probability of exploitation in the near term. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could exploit the vulnerability by sending crafted HTTP requests to the plugin’s management endpoints, potentially bypassing authentication checks to elevate privileges or tamper with classifieds content.
OpenCVE Enrichment