CVE-2025-15700: AWP Classifieds < 4.4.9 - Admin+ Arbitrary File Upload via ZIP Import
The AWP Classifieds WordPress plugin before 4.4.9 does not validate the type of files extracted from an uploaded ZIP archive during its listing-import feature, allowing users with the AWP Classifieds WordPress plugin before 4.4.9's management capability to upload arbitrary PHP files to a publicly accessible, network-shared directory and achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs the AWP Classifieds management capability. This is an admin-level or similarly privileged role within the plugin, so unauthenticated and ordinary low-privilege WordPress users are not described as affected.
What access or feature is required for exploitation?
The attacker must be able to use the plugin's listing-import feature and upload a ZIP archive. The vulnerable import process extracts files without validating their type.
What is the impact after a successful upload?
A malicious ZIP can place arbitrary PHP files in a publicly accessible, network-shared directory. An attacker can then achieve remote code execution.
How can I determine whether my site is affected?
Check whether AWP Classifieds is installed and running a version earlier than 4.4.9, and whether accounts have the plugin's management capability and access to listing imports. Review imported ZIP archives and the publicly accessible shared directory for unexpected PHP files.