Junglewise Threat Intelligence

CVE-2026-59550: Strategy11 AWP Classifieds SQL injection

CVE-2026-59550 · Severity: critical · CVSS 9.3 · Published 2026-07-27

Technologies: Strategy11 AWP Classifieds. Vendors: Strategy11.

Executive brief

AWP Classifieds is a popular WordPress plugin used to create and manage classified advertisement sections on websites. A critical security flaw allows unauthenticated attackers to interact directly with the site's database, potentially leading to the theft of sensitive customer data or administrative credentials. This vulnerability is highly dangerous as it can be exploited remotely without any user interaction or login credentials.

Technical details

A SQL injection vulnerability exists in the AWP Classifieds plugin (another-wordpress-classifieds-plugin) for WordPress in versions up to and including 4.4.7. The flaw is caused by improper neutralization of special elements used in an SQL command (CWE-89), allowing an unauthenticated attacker to append malicious SQL queries to legitimate requests. This can lead to unauthorized data extraction from the WordPress database, including user tables and configuration data. The vulnerability is reachable over the network without any prior authentication or user interaction. A fix is available in version 4.4.8.

Affected products

  • Strategy11 Team AWP Classifieds (Another WordPress Classifieds Plugin) <= 4.4.7

Timeline

  • 2026-07-14: disclosed: Reported by Thaer Assfour
  • 2026-07-23: advisory: Patchstack advisory published
  • 2026-07-27: patched: Version 4.4.8 released to address the issue

References

Related threats