ZeroHour

CVE-2026-84819

moderate

Unauthenticated Cross-Site Scripting (XSS) in WPAdverts WordPress plugin (<= 2.3.3)

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-84819 is an unauthenticated cross-site scripting (CWE-79) flaw in the WPAdverts classifieds plugin for WordPress, affecting all versions up to and including 2.3.3. Because no authentication is required (PR:N) and the attack occurs over the network, an attacker can inject malicious script via the plugin's front-end features and get it executed by tricking a user, such as a site administrator, into viewing a crafted page or submission. Successful exploitation lets the attacker run attacker-controlled JavaScript in the victim's browser, potentially enabling session hijacking, unauthorized admin actions, or defacement of the classifieds content. Any WordPress site running the WPAdverts plugin at version 2.3.3 or older is affected. There is currently no public proof-of-concept, the issue is not listed in CISA's Known Exploited Vulnerabilities catalog, and no exploitation has been reported.

What to do: Update WPAdverts to the latest patched release (any version newer than 2.3.3) as soon as possible. Until patched, review recent user-submitted ad content and consider WAF rules that block script injection into plugin endpoints, and watch for suspicious admin-account activity. Note that no fixed version number or public exploit was provided in the source data, so verify the patched release on the plugin's official listing.

Affected
WPAdverts WordPress plugin<= 2.3.3
Estimated exposure
moderateroughly 10,000-20,000 sites (WordPress.org lists the free WPAdverts plugin at approximately 10,000+ active installs) — The WordPress.org plugin directory's active-install listing for WPAdverts, which shows on the order of 10,000+ active installations, is used as the proxy for affected sites.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.