Record summary

CVE-2022-3254 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 1, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 6, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds

CVE List4.3 to < 4.3affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALAWP Classifieds <= 4.2.1 - Unauthenticated SQL Injection

WordPress Classifieds Plugin before 4.3 contains a SQL injection caused by improper sanitization and escaping of parameters in an AJAX action, letting unauthenticated attackers execute arbitrary SQL commands, exploit requires the premium module to be active.

Impact

Attackers can execute arbitrary SQL commands, potentially leading to data theft, data tampering, or full database compromise.

Remediation

Update to version 4.3 or later.

AuthorsShivam Kamboj
Template tagscvecve2022sqliwordpresswp-pluginawpcpunauthwpvkev

Source: ProjectDiscovery

References

2