Sceawere
Vulnerability Detail
CVE-2026-100178UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WPAdverts Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 2h ago
- Vendor
- gwin
- Product
- WPAdverts – Classifieds Plugin
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'adverts_location' parameter in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-10T08:17:03.070Z",
"pubdate": "2026-10-10T08:17:03.070Z",
"executiveSummary": "The WPAdverts – Classifieds Plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 2.3.4. This vulnerability arises from inadequate input sanitization and output escaping mechanisms applied to the 'adverts_location' parameter.\nThe flaw allows unauthenticated remote attackers to inject malicious JavaScript payloads into the plugin's data fields. When a victim, such as an administrator or another site user, views the affected pages containing the injected data, the payload executes within the context of their browser session.\nThe impact includes potential account takeover, session hijacking, unauthorized actions performed on behalf of the victim, and the redirection of users to malicious third-party domains. Because the vulnerability is exploitable by unauthenticated attackers without specific privilege requirements, it poses a significant risk to the integrity and security of the WordPress installation.\nSuccessful exploitation depends on the ability of the attacker to submit data through the vulnerable parameter, which is then rendered on the front-end or back-end without proper sanitization or context-aware encoding.",
"technicalDetails": "The root cause of this vulnerability is the failure of the WPAdverts plugin to properly sanitize user-supplied input submitted via the 'adverts_location' parameter before storing it in the database. Furthermore, the application fails to perform adequate context-aware output encoding when rendering this stored data in HTML templates.\nIn a standard XSS attack flow, the attacker performs an HTTP POST request targeting the endpoint responsible for updating the classified ad location. By injecting a crafted payload—such as <script>alert('XSS')</script> or more sophisticated obfuscated JavaScript—into the 'adverts_location' parameter, the attacker forces the application to persist the malicious string in the underlying WordPress database.\nWhen a legitimate user or administrator navigates to the compromised ad listing, the plugin retrieves the malicious script from the database and embeds it directly into the HTML response document. Because the application lacks sufficient output escaping, the browser interprets the injected script as legitimate code and executes it within the security context of the origin domain.\nBecause the 'adverts_location' input is not restricted to expected geographical formatting, an attacker can submit arbitrary tags and attributes. The execution context is global to the victim's session; therefore, if the victim is a privileged user (e.g., an administrator), the attacker can execute administrative actions, modify plugin settings, create new user accounts with elevated permissions, or exfiltrate sensitive cookies and session tokens.\nThis vulnerability is classified as Stored XSS because the payload is persistent; it executes every time the affected page is loaded, increasing the probability of a successful attack against multiple targets without requiring ongoing interaction from the attacker after the initial injection. The vulnerability is accessible over the network and requires no specific authentication or authorization, as the input vector is available to any user or visitor capable of interacting with the plugin's submission or update forms."
}