CVE-2026-24593: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-24593 is a Sensitive Data Exposure vulnerability (CWE-497) in the AWP Classifieds WordPress plugin developed by Strategy11 Team. It allows unauthenticated remote attackers to retrieve embedded sensitive system information. The vulnerability affects AWP Classifieds versions up to and including 4.4.3. It was published on January 23, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium), assigned by CISA-ADP (Feedly, Patchstack).

Technical details

The vulnerability is classified under CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere), meaning the plugin inadvertently exposes sensitive system-level data to parties that should not have access to it. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker. The associated CAPEC pattern is CAPEC-170 (Web Application Fingerprinting), suggesting the exposed data could be leveraged to gather intelligence about the underlying system or WordPress environment. Technical details and proof-of-concept specifics are documented by Patchstack (Patchstack).

Impact

Successful exploitation results in a low-level confidentiality impact, with no effect on integrity or availability. An unauthenticated attacker can retrieve sensitive system information embedded within the plugin, which may include configuration details, internal paths, or environment data that could facilitate further reconnaissance or targeted attacks against the WordPress installation. While the direct impact is limited, the exposed data could serve as a stepping stone for more severe follow-on attacks (Feedly).

Exploitability

The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it accessible to a wide range of threat actors. The EPSS score is approximately 0.009% (0.000090), indicating a currently low probability of active exploitation in the wild. There is no evidence of in-the-wild exploitation, no known exploit kits or weaponized code, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the available data (Feedly).

Mitigation and workarounds

Users should update the AWP Classifieds WordPress plugin to a version beyond 4.4.3, which is the last known vulnerable release. Site administrators should check the WordPress plugin repository or the vendor's official channels for a patched release. As a general workaround, restricting public access to sensitive plugin endpoints via web server rules (e.g., .htaccess or nginx configuration) may reduce exposure until a patch is applied (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management