CVE-2026-84819
moderateUnauthenticated Cross-Site Scripting (XSS) in WPAdverts WordPress plugin (<= 2.3.3)
CVE-2026-84819 is an unauthenticated cross-site scripting (CWE-79) flaw in the WPAdverts classifieds plugin for WordPress, affecting all versions up to and including 2.3.3. Because no authentication is required (PR:N) and the attack occurs over the network, an attacker can inject malicious script via the plugin's front-end features and get it executed by tricking a user, such as a site administrator, into viewing a crafted page or submission. Successful exploitation lets the attacker run attacker-controlled JavaScript in the victim's browser, potentially enabling session hijacking, unauthorized admin actions, or defacement of the classifieds content. Any WordPress site running the WPAdverts plugin at version 2.3.3 or older is affected. There is currently no public proof-of-concept, the issue is not listed in CISA's Known Exploited Vulnerabilities catalog, and no exploitation has been reported.
What to do: Update WPAdverts to the latest patched release (any version newer than 2.3.3) as soon as possible. Until patched, review recent user-submitted ad content and consider WAF rules that block script injection into plugin endpoints, and watch for suspicious admin-account activity. Note that no fixed version number or public exploit was provided in the source data, so verify the patched release on the plugin's official listing.
| WPAdverts WordPress plugin | <= 2.3.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.