Impact
An unauthenticated Cross Site Scripting flaw exists in the WordPress WPAdverts plugin version 2.3.3 and earlier. This weakness allows an attacker to inject malicious script code that would run in the browsers of visitors who view affected content, giving the attacker the ability to hijack sessions, deface pages, or perform phishing attacks. The flaw is a classic input validation problem identified as CWE-79.
Affected Systems
All installations of the WPAdverts WordPress plugin that are at version 2.3.3 or earlier are affected. Operators of any WordPress site that have not upgraded the plugin are exposed to the risk of client‑side script injection via the plugin’s input interfaces.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity. Based on the description, the XSS flaw can be triggered by an unauthenticated user submitting malicious content through the plugin from any web‑connected client. The EPSS score is not available, leaving the probability of exploitation uncertain. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, so no confirmed exploitation has been reported.
OpenCVE Enrichment