CVE-2026-84819: WordPress WPAdverts plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WPAdverts pluginto a version that resolves this vulnerability.Fixed in 2.3.4
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
The issue is described as unauthenticated, so an attacker does not need a WordPress account or other prior privileges. The vector is network-based and requires user interaction.
Which installations are affected?
WPAdverts versions 2.3.3 and earlier are affected according to the available information. The provided data does not identify any configuration prerequisite or workaround for unpatched sites.
What impact can a successful exploit have?
The stated XSS impact includes low confidentiality, integrity, and availability effects, with scope changed. Because exploitation requires user interaction, the available data indicates an attacker must cause a user to interact with the malicious content.