Junglewise Threat Intelligence

CVE-2026-42726: Strategy11 AWP Classifieds missing authorization in WordPress plugin

CVE-2026-42726 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: Strategy11 AWP Classifieds. Vendors: Strategy11.

Executive brief

AWP Classifieds is a popular WordPress plugin used to create and manage classified advertisement sections on websites. A security flaw in the plugin's access control settings allows unauthorized users to perform actions they should not be permitted to do. This could lead to unauthorized changes to classified listings or disruption of the advertisement service, potentially impacting site revenue and user trust.

Technical details

The AWP Classifieds plugin for WordPress (versions up to and including 4.4.5) suffers from a Broken Access Control vulnerability (CWE-862). The flaw stems from missing authorization checks or incorrectly configured security levels within the plugin's functional logic. An unauthenticated remote attacker can exploit this to execute actions that should be restricted to higher-privileged users. While the CVSS vector indicates no direct impact on confidentiality, it confirms potential impacts on integrity and availability. The issue is resolved in version 4.4.6.

Affected products

  • Strategy11 Team AWP Classifieds (another-wordpress-classifieds-plugin) <= 4.4.5

Timeline

  • 2026-04-11: other: Vulnerability reported by researcher she11f
  • 2026-05-12: advisory: Initial advisory published by Patchstack
  • 2026-05-27: disclosed: CVE published to NVD dataset

References

Related threats