Impact
The vulnerability arises from insufficient sanitization and escaping of the adverts_location parameter in WPAdverts. An attacker can inject arbitrary JavaScript that is stored and later served in augmented listing pages. Once executed in a user's browser, the injected code can steal session cookies, deface content, or perform further malicious actions. The weakness is a classic XSS flaw (CWE‑79) that allows client‑side code execution, compromising confidentiality, integrity, and availability of the site’s user interactions.
Affected Systems
WordPress sites that use the WPAdverts – Classifieds Plugin, version 2.3.4 and earlier, supplied by the gwin vendor. Any instance of this plugin in those releases is affected.
Risk and Exploitability
The CVSS score of 7.2 reflects a high‑severity vulnerability. With an EPSS score not available, the exact likelihood of exploitation is unclear but the lack of authentication requirements indicates that any web‑connected user could attempt the attack. The vulnerability is not listed in CISA KEV, but the stored nature and impact on user sessions mean that organisations should treat it as a serious threat and act promptly.
OpenCVE Enrichment