CVE-2025-57928: WordPress AWP Classifieds plugin <= 4.4.3 - Content Injection vulnerability
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Team AWP Classifieds allows Code Injection. This issue affects AWP Classifieds: from n/a through 4.3.5.
Other sources
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Code Injection.This issue affects AWP Classifieds: from n/a through <= 4.4.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57928?
CVE-2025-57928 has a high severity level due to its potential for code injection through improper neutralization of script-related HTML tags.
How do I fix CVE-2025-57928?
To fix CVE-2025-57928, upgrade your AWP Classifieds plugin to version 4.3.6 or later.
Which versions are affected by CVE-2025-57928?
CVE-2025-57928 affects all versions of AWP Classifieds from n/a up to 4.3.5.
What type of vulnerability is CVE-2025-57928?
CVE-2025-57928 is classified as a basic cross-site scripting (XSS) vulnerability.
What products are impacted by CVE-2025-57928?
CVE-2025-57928 impacts the Strategy11 Team AWP Classifieds and WordPress AWP Classifieds Plugin.