{"id":"CVE-2025-15700","title":"The AWP Classifieds WordPress plugin before 4.4.9 does not validate the type of files extracted from an uploaded ZIP archive during its listing-import feature, allowing users with the AWP Classifieds WordPress plugin before 4.4.9's manag…","summary":"The AWP Classifieds WordPress plugin before 4.4.9 does not validate the type of files extracted from an uploaded ZIP archive during its listing-import feature, allowing users with the AWP Classifieds WordPress plugin before 4.4.9's manag…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-434"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T15:17:05.333","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-15700","references":[{"url":"https://wpscan.com/vulnerability/6d3e7721-41d4-4e5f-9a44-c601f0cdfe50/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00194,"epssPercentile":0.08333,"ingestedAt":"2026-10-09T07:28:22.263Z","slug":"CVE-2025-15700","body":"## Overview\n\nThe AWP Classifieds WordPress plugin before 4.4.9 does not validate the type of files extracted from an uploaded ZIP archive during its listing-import feature, allowing users with the AWP Classifieds WordPress plugin before 4.4.9's management capability to upload arbitrary PHP files to a publicly accessible, network-shared directory and achieve remote code execution.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":218532,"id":"CVE-2025-15700","ts":1791561810668,"field":"cvss","old":null,"new":"8.8"},{"seq":218531,"id":"CVE-2025-15700","ts":1791561810668,"field":"severity","old":"none","new":"high"}]}