CVE-2026-97263: WordPress WPAdverts plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts allows Stored XSS.This issue affects WPAdverts: from n/a through 2.3.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WPAdverts (wpadverts)to a version that resolves this vulnerability.Fixed in 2.3.5
Event History
Frequently Asked Questions
Which WPAdverts installations are affected?
WPAdverts versions through 2.3.4 are affected. The available data does not identify any configuration prerequisite or unaffected earlier version.
What does an attacker need to exploit this issue?
The vulnerability is network-accessible and has low attack complexity, with no privileges required. Exploitation requires user interaction, meaning a victim must interact with attacker-controlled content.
What is the likely impact if exploitation succeeds?
This is a stored XSS issue. The provided severity vector indicates low impacts to confidentiality, integrity, and availability, with the impact scope extending beyond the vulnerable component.