Junglewise Threat Intelligence

CVE-2026-39533: WPTasty AWP Classifieds broken access control

CVE-2026-39533 · Severity: high · CVSS 7.5 · Published 2026-06-15

Executive brief

AWP Classifieds is a popular WordPress plugin used to create and manage classified advertisement listings. A security flaw in versions 4.4.4 and earlier allows unauthorized individuals to perform actions that should be restricted to administrators or registered users. This could lead to service disruptions or unauthorized changes to the classifieds platform, potentially impacting the site's availability and reputation.

Technical details

A broken access control vulnerability exists in the AWP Classifieds plugin for WordPress due to missing authorization checks (CWE-862). The flaw allows an unauthenticated remote attacker to execute functions or actions that should require higher privileges. According to the CVSS vector, the primary impact is on system availability (A:H), suggesting that the unauthorized actions may allow for the deletion of data or disruption of plugin services. The vulnerability is resolved in version 4.4.5.

Affected products

  • WPTasty AWP Classifieds <= 4.4.4

Timeline

  • 2026-02-11: other: Reported by Dahmani Toumi
  • 2026-04-08: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References