Impact
WPAdverts plugin contains improper neutralization of input during web page generation, enabling a DOM‑based cross‑site scripting attack that allows an attacker to inject arbitrary JavaScript that executes in the victim’s browser.
Affected Systems
The vulnerability exists in the Greg Winiarski WPAdverts plugin for WordPress, affecting all releases from the first published version through version 2.2.5 inclusive. Any WordPress installation that has this plugin installed and active is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The flaw is not listed in the CISA KEV catalog. Because the issue is DOM‑based, an attacker only needs a victim to visit a page rendered by the plugin; no additional authentication is required.
OpenCVE Enrichment
EUVD