Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPeka WP AdCenter wpadcenter allows Stored XSS.This issue affects WP AdCenter: from n/a through <= 2.6.1.
Published: 2025-10-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP AdCenter plugin includes unsanitized input handling that allows malicious JavaScript to be persisted in the database. When an attacker injects script through any plugin data field, the content is later rendered in user‑visible pages, causing the script to run in the visitor’s browser. This can enable an attacker to steal session cookies, deface the site, or execute further client‑side attacks, but the CVE description does not detail specific post‑execution outcomes. The vulnerability therefore represents a true stored XSS flaw that compromises client‑side integrity and confidentiality for anyone who views the affected pages.

Affected Systems

The issue affects the WPeka WP AdCenter plugin for WordPress, versions through and including 2.6.1. WordPress sites that have this plugin installed and in use are at risk, particularly if the plugin’s advertisement or content fields are publicly displayed.

Risk and Exploitability

The CVSS score is 6.5, indicating moderate severity. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is currently not listed in the CISA KEV catalog. The attack likely requires the attacker to supply malicious input via the plugin’s data interface, which is usually restricted to administrators; thus, privileged access is a prerequisite for exploitation. Once injected, the payload is served to all site visitors who view the content, creating a wide impact scope without additional network-level compromise.

Generated by OpenCVE AI on April 29, 2026 at 23:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WP AdCenter to the latest released version (greater than 2.6.1).
  • If an update is unavailable, disable the plugin on public‑facing sections of the site or restrict access to the plugin’s input interfaces to trusted administrators only.
  • Remove or sanitize any stored content that may contain injected scripts; this includes clearing ad content fields or resetting them to safe values.

Generated by OpenCVE AI on April 29, 2026 at 23:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpeka
Wpeka wp Adcenter
Vendors & Products Wordpress
Wordpress wordpress
Wpeka
Wpeka wp Adcenter

Mon, 27 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Oct 2025 02:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPeka WP AdCenter wpadcenter allows Stored XSS.This issue affects WP AdCenter: from n/a through <= 2.6.1.
Title WordPress WP AdCenter plugin <= 2.6.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
Wpeka Wp Adcenter
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T19:00:06.727Z

Reserved: 2025-10-24T14:25:13.438Z

Link: CVE-2025-62984

cve-icon Vulnrichment

Updated: 2025-10-27T13:18:54.947Z

cve-icon NVD

Status : Deferred

Published: 2025-10-27T02:15:59.333

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-62984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T23:30:22Z

Weaknesses