PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Feb 10, 2026

AWP Classifieds <= 4.2.1 - Unauthenticated SQL Injection

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds
AFFECTED< 4.3SAFE ✓≥ 4.3
Updated Sep 18, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

AWP Classifieds <= 4.2.1 - Unauthenticated SQL Injection Scanner | S4E