Remote Code Execution Vulnerability in AWP Classifieds Plugin by WordPress
CVE-2025-15700
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 9 October 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2025-15700?
The AWP Classifieds plugin for WordPress prior to version 4.4.9 has a significant vulnerability in its listing-import feature. It fails to properly validate the type of files that users can extract from uploaded ZIP archives. Consequently, users with management capabilities can upload arbitrary PHP files to a publicly accessible directory. This security flaw can lead to unauthorized remote code execution, posing substantial risks to the integrity of the affected WordPress sites.
Affected Version(s)
AWP Classifieds 0 < 4.4.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.