Impact
The vulnerability in WPAdverts allows an attacker to inject malicious scripts through unsanitized input. This DOM‑based XSS flaw can embed arbitrary JavaScript into the page generated by the plugin, potentially compromising confidentiality and integrity when a victim views the affected page. The flaw is identified by CWE‑79.
Affected Systems
The flaw affects the WPAdverts WordPress plugin in all releases up to and including version 2.2.3. Any WordPress site that has installed WPAdverts 2.2.3 or earlier is vulnerable. No specific WordPress core versions are mentioned, so all installations running a vulnerable plugin version are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% reflects a very low but non‑zero probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this flaw by causing a victim’s browser to load a crafted URL or input that the plugin renders without sanitization; the attack vector is client‑side and does not require special privileges or credentials. This inference is based on the description of a DOM‑based XSS flaw.
OpenCVE Enrichment
EUVD