CVE-2025-49878: WordPress WPAdverts plugin <= 2.2.4 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts allows DOM-Based XSS. This issue affects WPAdverts: from n/a through 2.2.4.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts allows DOM-Based XSS.This issue affects WPAdverts: from n/a through <= 2.2.4.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49878?
CVE-2025-49878 is classified as a high-severity vulnerability due to the potential for DOM-based cross-site scripting (XSS) attacks.
How do I fix CVE-2025-49878?
To fix CVE-2025-49878, update WPAdverts to the latest version beyond 2.2.4 where the vulnerability is patched.
What systems are affected by CVE-2025-49878?
CVE-2025-49878 affects versions of WPAdverts from n/a through 2.2.4.
What type of vulnerability is CVE-2025-49878?
CVE-2025-49878 is a Cross-Site Scripting (XSS) vulnerability that allows for improper neutralization of input during web page generation.
Can CVE-2025-49878 be exploited remotely?
Yes, CVE-2025-49878 can be exploited remotely by an attacker to execute malicious scripts in the context of the user's browser.