
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24593 is a Sensitive Data Exposure vulnerability (CWE-497) in the AWP Classifieds WordPress plugin developed by Strategy11 Team. It allows unauthenticated remote attackers to retrieve embedded sensitive system information. The vulnerability affects AWP Classifieds versions up to and including 4.4.3. It was published on January 23, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium), assigned by CISA-ADP (Feedly, Patchstack).
The vulnerability is classified under CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere), meaning the plugin inadvertently exposes sensitive system-level data to parties that should not have access to it. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker. The associated CAPEC pattern is CAPEC-170 (Web Application Fingerprinting), suggesting the exposed data could be leveraged to gather intelligence about the underlying system or WordPress environment. Technical details and proof-of-concept specifics are documented by Patchstack (Patchstack).
Successful exploitation results in a low-level confidentiality impact, with no effect on integrity or availability. An unauthenticated attacker can retrieve sensitive system information embedded within the plugin, which may include configuration details, internal paths, or environment data that could facilitate further reconnaissance or targeted attacks against the WordPress installation. While the direct impact is limited, the exposed data could serve as a stepping stone for more severe follow-on attacks (Feedly).
The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it accessible to a wide range of threat actors. The EPSS score is approximately 0.009% (0.000090), indicating a currently low probability of active exploitation in the wild. There is no evidence of in-the-wild exploitation, no known exploit kits or weaponized code, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the available data (Feedly).
Users should update the AWP Classifieds WordPress plugin to a version beyond 4.4.3, which is the last known vulnerable release. Site administrators should check the WordPress plugin repository or the vendor's official channels for a patched release. As a general workaround, restricting public access to sensitive plugin endpoints via web server rules (e.g., .htaccess or nginx configuration) may reduce exposure until a patch is applied (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."