WordPress Plugin Vulnerabilities
AWP Classifieds < 4.4.9 - Admin+ Arbitrary File Upload via ZIP Import
Description
The plugin does not validate the type of files extracted from an uploaded ZIP archive during its listing-import feature, allowing users with the plugin's management capability to upload arbitrary PHP files to a publicly accessible, network-shared directory and achieve remote code execution.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Khaled Alenazi (Nxploited)
Submitter
Khaled Alenazi (Nxploited)
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-10-07 (about 2 days ago)
Added
2026-10-07 (about 1 day ago)
Last Updated
2026-10-07 (about 1 day ago)