Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-39533

CVE-2026-39533: AWP Classifieds Auth Bypass Vulnerability

CVE-2026-39533 is an authentication bypass flaw in AWP Classifieds plugin versions 4.4.4 and earlier due to broken access control. This vulnerability allows unauthorized access. Learn about affected versions and fixes.

Published:

CVE-2026-39533 Overview

CVE-2026-39533 is an unauthenticated broken access control vulnerability affecting the Another WordPress Classifieds Plugin (AWP Classifieds) in versions up to and including 4.4.4. The flaw is categorized under [CWE-862] Missing Authorization, allowing remote attackers to interact with protected plugin functionality without supplying credentials. Successful exploitation impacts the availability of the affected WordPress site. The vulnerability is reachable over the network with low attack complexity and requires no user interaction, making any internet-exposed WordPress instance running the affected plugin a viable target.

Critical Impact

Unauthenticated remote attackers can abuse missing authorization checks in AWP Classifieds <= 4.4.4 to disrupt site availability without credentials or user interaction.

Affected Products

  • Another WordPress Classifieds Plugin (AWP Classifieds) versions up to and including 4.4.4
  • WordPress sites with the plugin installed and active
  • Any deployment exposing the plugin endpoints to untrusted networks

Discovery Timeline

  • 2026-06-15 - CVE-2026-39533 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2026-39533

Vulnerability Analysis

The vulnerability stems from missing authorization checks in the AWP Classifieds plugin. One or more plugin endpoints accept requests from unauthenticated clients and execute privileged actions without verifying the caller's identity or capabilities. This is a textbook [CWE-862] Missing Authorization defect, where the application relies on obscurity or client-side gating rather than server-side capability checks.

The impact profile focuses on availability. An attacker can trigger state-changing operations that disrupt the classifieds functionality or the underlying WordPress site, while confidentiality and integrity of stored data are not directly compromised by this specific flaw. Because the issue is network-reachable and requires neither credentials nor user interaction, automated scanners and opportunistic attackers can exploit vulnerable instances at scale.

Root Cause

The plugin fails to enforce capability or nonce verification on sensitive request handlers. WordPress provides primitives such as current_user_can() and check_ajax_referer() to gate privileged operations, but the affected handlers in AWP Classifieds <= 4.4.4 do not invoke these checks before performing their actions.

Attack Vector

Exploitation occurs over HTTP(S) against the WordPress site hosting the vulnerable plugin. An attacker sends a crafted request to a plugin endpoint, typically through admin-ajax.php or a registered REST route, and the server executes the requested action without authenticating the caller. The Patchstack advisory documents the specific endpoints and parameters involved. Refer to the Patchstack Vulnerability Report for technical specifics.

Detection Methods for CVE-2026-39533

Indicators of Compromise

  • Unauthenticated POST requests to AWP Classifieds endpoints in admin-ajax.php access logs, particularly from a small set of source IPs issuing high request volumes
  • Unexpected modifications, deletions, or state changes to classifieds listings without a corresponding authenticated administrator session
  • WordPress error logs showing fatal errors or resource exhaustion correlated with plugin handler invocations

Detection Strategies

  • Inventory all WordPress installations and identify sites running AWP Classifieds at version 4.4.4 or earlier using plugin enumeration
  • Deploy WAF rules that flag unauthenticated requests targeting AWP Classifieds AJAX actions and REST routes
  • Correlate web server access logs with plugin behavior to identify anomalous request patterns against the plugin namespace

Monitoring Recommendations

  • Enable verbose access logging on the WordPress front controller and forward logs to a centralized analytics platform
  • Alert on spikes in admin-ajax.php traffic without authenticated session cookies
  • Monitor site availability and database write rates for sudden anomalies that may indicate exploitation attempts

How to Mitigate CVE-2026-39533

Immediate Actions Required

  • Identify and patch all instances of AWP Classifieds running version 4.4.4 or earlier across the WordPress estate
  • Restrict access to the plugin endpoints at the network or WAF layer until patching is complete
  • Audit recent plugin activity for signs of exploitation, focusing on unauthenticated state changes

Patch Information

Apply the vendor-released update that addresses the broken access control issue. Consult the Patchstack Vulnerability Report for the fixed version and update guidance. Verify the plugin version after upgrade and confirm that the previously vulnerable endpoints now enforce authorization.

Workarounds

  • Deactivate the AWP Classifieds plugin until a patched version can be installed if the classifieds feature is non-essential
  • Apply virtual patching at the WAF to block unauthenticated requests to known vulnerable plugin endpoints
  • Restrict access to /wp-admin/admin-ajax.php action parameters associated with the plugin to authenticated administrators using server configuration rules

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.