Impact
Based on the description, it is inferred that the WPAdverts plugin for WordPress contains an unauthenticated Cross‑Site Scripting vulnerability (CWE‑79) that allows an attacker to inject arbitrary JavaScript into pages generated by the plugin. The flaw handled by the plugin, which results in script execution in the browsers of any visitor to affected pages. The impact is confined to the client side and does not compromise the WordPress server or administrative accounts.
Affected Systems
All WordPress sites that have Greg Winiarski’s WPAdverts plugin version 2.3.1 or earlier installed are affected. Sites running newer releases are not vulnerable; if an upgrade cannot be performed immediately, removing or disabling the plugin removes the attack surface.
Risk and Exploitability
The CVSS score of 7.1 classifies the flaw as high severity, while the EPSS < 1% indicates that exploitation attempts are currently rare. The vulnerability is not listed in CISA’s KEV catalog. Because authentication is not required, attack vector is a direct submission of crafted input via the plugin’s forms or other entry points, which is inferred from the nature of the XSS flaw described.
OpenCVE Enrichment