Strategy11
Strategy11 AWP Classifieds: vulnerabilidades y CVE
Strategy11 AWP Classifieds tiene 9 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses3
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-59550 | Crítica (9.3) | 0.40% | — | 27 jul 2026 | Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions. |
| CVE-2026-5100 | Alta (7.5) | 0.69% | — | 5 may 2026 | The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4.4.5 due to insufficient escaping on the user supplied parameter and lack… |
| CVE-2026-24593 | Media (5.3) | 0.34% | — | 23 ene 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Retrieve Embedded Sensitive Data.This issue affects… |
| CVE-2024-31350 | Alta (8.8) | 0.32% | — | 9 jun 2024 | Missing Authorization vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1. |
| CVE-2024-32447 | Media (4.3) | 0.21% | — | 15 abr 2024 | Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1. |
| CVE-2023-41801 | Alta (8.8) | 0.25% | — | 6 oct 2023 | Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugin <= 4.3 versions. |
| CVE-2022-3254 | Crítica (9.8) | 5.6% | — | 31 oct 2022 | The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a… |
| CVE-2014-10013 | Alta (7.5) | 4.6% | — | 13 ene 2015 | SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action. |
| CVE-2014-10012 | Media (4.3) | 1.6% | — | 13 ene 2015 | Cross-site scripting (XSS) vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.