Extension WordPress
Vulnérabilités AWP Classifieds
Cette page rassemble les failles publiées pour AWP Classifieds, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de AWP Classifieds
13 fiches
AWP Classifieds <= 4.4.5 – Missing Authorization
The AWP Classifieds plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.4.5. This makes it possible for unauthenticated attackers to perform an unauthorized…
*-4.4.5
4.4.6
12/05/2026
AWP Classifieds <= 4.4.6 – Unauthenticated SQL Injection via 'regions'
The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-4.4.6
4.4.6.1
04/05/2026
AWP Classifieds <= 4.4.4 – Missing Authorization
The AWP Classifieds plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.4.4. This makes it possible for unauthenticated attackers to perform an…
*-4.4.4
4.4.5
08/04/2026
AWP Classifieds <= 4.4.3 – Unauthenticated Information Exposure
The AWP Classifieds plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
*-4.4.3
4.4.4
16/01/2026
AWP Classifieds <= 4.4.3 – Unauthenticated Arbitrary Shortcode Execution
The The WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.4.3. This is due to the software allowing users…
*-4.4.3
4.4.4
22/09/2025
AWP Classifieds <= 4.3.1 – Cross-Site Request Forgery
The AWP Classifieds plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.1. This is due to missing or incorrect nonce validation on the ajax() function. This makes it possible for unauthenticated…
*-4.3.1
4.3.2
12/04/2024
AWP Classifieds <= 4.3.1 – Missing Authorization
The AWP Classifieds plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.3.1. This makes it possible for authenticated attackers, with subscriber-level access and…
*-4.3.1
4.3.2
05/04/2024
AWP Classifieds <= 4.3 – Cross-Site Request Forgery
The AWP Classifieds plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3. This is due to missing nonce validation on several functions such as dispatch(), try_to_delete_categories(), try_to_update_category(), try_to_move_categories(), and more. This…
*-4.3
4.3.1
05/09/2023
AWP Classifieds <= 4.2.1 – Unauthenticated SQL Injection
The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 4.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
*-4.2.1
4.3
10/10/2022
WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds <= 3.3.1 – Cross-Site Scripting
The WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error_message’ parameter in versions up to, and including, 3.3.1 due to insufficient input sanitization and…
*-3.3.1
3.3.2
09/12/2014
WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds < 3.0 – SQL Injection
SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action.
[*, 3.0)
3.0
10/11/2014
WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds < 3.0 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.
[*, 3.0)
3.0
08/11/2014
WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds < 2.0 – Arbitrary File Upload
The WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the admin_handleimagesupload function in versions up to, and including, 1.8.9.4.…
[*, 2.0)
2.0
03/04/2012
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.