CVE-2022-3254
AWP Classifieds Plugin < 4.3 - Unauthenticated SQLi
Record summary
CVE-2022-3254 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 1, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 6, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds | CVE List | 4.3 to < 4.3 | affected |
awp_classifiedsBrowse strategy11 / awp_classifieds | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALAWP Classifieds <= 4.2.1 - Unauthenticated SQL Injection
WordPress Classifieds Plugin before 4.3 contains a SQL injection caused by improper sanitization and escaping of parameters in an AJAX action, letting unauthenticated attackers execute arbitrary SQL commands, exploit requires the premium module to be active.
Impact
Attackers can execute arbitrary SQL commands, potentially leading to data theft, data tampering, or full database compromise.
Remediation
Update to version 4.3 or later.
Source: ProjectDiscovery