Sceawere
Vulnerability Detail
CVE-2026-97264UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in WPAdverts Plugin
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 2h ago
- Vendor
- Greg Winiarski
- Product
- WPAdverts
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts allows Reflected XSS.This issue affects WPAdverts: from n/a through 2.3.4.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-10T14:16:38.367Z",
"pubdate": "2026-10-10T14:16:38.367Z",
"executiveSummary": "The WPAdverts plugin for WordPress, specifically versions up to and including 2.3.4, contains a security vulnerability classified as Improper Neutralization of Input During Web Page Generation, commonly referred to as Cross-Site Scripting (XSS).\nThis vulnerability is categorized as Reflected XSS, where the application fails to adequately sanitize user-supplied input before reflecting it back to the web browser.\nAn unauthenticated remote attacker can exploit this flaw by crafting malicious URLs containing JavaScript payloads. When a victim, such as an administrator or a standard user, interacts with the compromised link, the malicious script executes within their browser session.\nThe impact of this vulnerability is significant, as it allows attackers to bypass same-origin policy protections to execute arbitrary JavaScript. Potential consequences include the theft of sensitive session cookies, unauthorized administrative actions, redirection to malicious domains, or the exfiltration of user data stored within the browser's context.\nBecause this requires user interaction, the risk is highly dependent on social engineering tactics, though the lack of authentication requirements broadens the attack surface to any visitor of the affected WordPress site.\nUsers of the WPAdverts plugin are at risk of account takeover and malicious site manipulation if their current version remains at or below 2.3.4.",
"technicalDetails": "The vulnerability resides within the request handling logic of the WPAdverts plugin, where input parameters are insufficiently neutralized before being rendered in the server-generated HTML response.\nReflected XSS occurs when an application receives data in an HTTP request and includes that data within the immediate response in an unsafe manner. In this instance, the plugin likely fails to implement proper output encoding or input validation on parameters transmitted via GET or POST requests.\nThe attack flow begins when an attacker identifies an unsanitized input parameter within the WPAdverts plugin. The attacker then constructs a URL containing an encoded malicious script payload, such as <script>alert(document.cookie)</script> or more sophisticated exfiltration vectors.\nWhen a legitimate user navigates to this crafted URL, the web server processes the request and embeds the payload directly into the HTML document returned to the victim. Because the browser perceives this injected code as originating from the legitimate, trusted domain of the WordPress site, it executes the payload in the victim's security context.\nBecause the payload executes within the context of the user's current session, it has full access to the Document Object Model (DOM), allowing the attacker to read session tokens, perform actions on behalf of the user, or modify the visual appearance of the page to conduct phishing attacks.\nSince the vulnerability exists within the plugin's core functionality, it is accessible over the network without requiring any prior authentication or special user privileges. This makes it an ideal vector for mass exploitation campaigns targeting WordPress installations that have not yet updated the component.\nThe root cause is the failure to utilize secure WordPress development practices, such as the use of esc_html(), esc_attr(), or esc_js() functions when outputting user-provided data into the theme or plugin templates. Without these sanitization layers, any character input that alters the HTML structure—such as angle brackets, quotes, or event handlers—remains active and executable by the browser's JavaScript engine.\nFollowing successful exploitation, the post-exploitation impact includes the potential for full site compromise if the victim possesses administrative privileges. By capturing administrative session identifiers, an attacker could potentially upload malicious plugins, modify site settings, or inject persistent backdoors into the database, transitioning the attack from a temporary reflected state to a permanent site-wide compromise."
}