CVE-2026-5100General

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-05-05); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-05: 2Mentions · 2026-05-18: 1Mentions · 2026-05-29: 1Mentions · 2026-05-30: 1Technical Details · 2026-05-05: 205-0505-1805-2905-30
Signal classification2 categories
General
360.0%
Disclosure
240.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-052
Disclosure1General1
2026-05-181
General1
2026-05-291
Disclosure1
2026-05-301
General1
Full discourse5 posts
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【脆弱性情報】 CVE-2026-5100 AWP Classifieds plugin for WordPressの脆弱性について https://www.cybernote.click/2026/05/18/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-5100-awp-classifieds-plugin-for-wordpress%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/ #IT #Security #cybersecurity

    Post summary

    The post announces a CVE (CVE-2026-5100) for the AWP Classifieds WordPress plugin, but provides no technical details, exploit information, or remedial guidance.

    0000041
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    【脆弱性情報】 CVE-2026-5100 AWP Classifieds plugin for WordPressの脆弱性について https://www.cybernote.click/2026/05/18/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-5100-awp-classifieds-plugin-for-wordpress%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/ #IT #Security #cybersecurity

    Post summary

    The post announces CVE‑2026‑5100 affecting the AWP Classifieds WordPress plugin, but provides no PoC, exploit code, active exploitation evidence, patch information, or technical details.

    0000045
    208 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【脆弱性情報】 CVE-2026-5100 AWP Classifieds plugin for WordPressの脆弱性について #cybernote #ブログ仲間と繋がりたい #Webライター https://www.cybernote.click/2026/05/18/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-5100-awp-classifieds-plugin-for-wordpress%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/

    Post summary

    The post announces a new CVE (CVE‑2026‑5100) affecting the AWP Classifieds WordPress plugin but provides no technical details, exploit information, or mitigation steps.

    0000069
    206 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-5100 SQL Injection in AWP Classifieds Plugin for WordPress Versions Up to 4.4.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5100

    Post summary

    The text references a SQL injection flaw (CVE‑2026‑5100) affecting AWP Classifieds Plugin up to version 4.4.5, but provides no additional details on exploitation, mitigation, or verification.

    0000053
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5100 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5100 #CVE-2026-5100 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/lB6GZCfk7D

    Post summary

    The tweet announces a new CVE (CVE-2026-5100) with a high severity score that affects WordPress, but it does not mention PoC, exploitation, or fixes.

    0000041
    151 followersView on X

Explore more