Impact
The vulnerability is a stored Cross‑Site Scripting flaw that allows an authenticated attacker with custom‑level privileges or higher to inject malicious JavaScript into the plugin’s "phone" field. Once stored, the script executes whenever a user views a page rendering that field, potentially compromising the credentials of any visitor and enabling session hijacking, defacement, or malware delivery. This is a classic reflected‑to‑stored XSS, classified under CWE‑79.
Affected Systems
All installations of the Advanced Classifieds & Directory Pro WordPress plugin up to version 3.4.4 are affected. The flaw exists in the code handling the "phone" parameter on listing pages and is tied to the plugin’s optional UI elements.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, and the EPSS is not available. The vulnerability is not listed in CISA KEV, suggesting no confirmed exploitation yet. Exploitation requires two non‑default settings: the "Force Bootstrap" miscellaneous option must be enabled, and the "ACADP Listing Address" widget must be placed on a sidebar that appears on single listing pages. Attackers must also possess custom‑level or higher WordPress user access, so the threat surface is limited to authenticated users with elevated permissions.
OpenCVE Enrichment