Junglewise Threat Intelligence

CVE-2026-65469: Strategy11 AWP Classifieds broken access control

CVE-2026-65469 · Severity: medium · CVSS 5.3 · Published 2026-07-23

Technologies: Strategy11 Team AWP Classifieds. Vendors: Strategy11.

Executive brief

AWP Classifieds is a popular WordPress plugin used to create and manage classified advertisement sections on websites. A security flaw in versions 4.4.7 and earlier allows unauthenticated visitors to perform actions that should be restricted to authorized users. While the immediate impact is considered low, it could allow unauthorized modifications to site content or settings, potentially affecting the integrity of the classifieds platform.

Technical details

A broken access control vulnerability exists in the AWP Classifieds plugin (another-wordpress-classifieds-plugin) for WordPress due to missing authorization checks (CWE-862). The flaw allows an unauthenticated remote attacker to execute functions or actions that should require higher privileges. According to the CVSS vector, the impact is limited to unauthorized integrity changes (I:L) with no impact on confidentiality or availability. The issue is resolved in version 4.4.8.

Affected products

  • Strategy11 Team AWP Classifieds <= 4.4.7

Timeline

  • 2026-07-09: other: Reported by researcher z3r0s
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: NVD publication date
  • 2026-07-23: patched: Patch confirmed available in version 4.4.8

References

Related threats