CVE-2026-97264: WordPress WPAdverts plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts allows Reflected XSS.This issue affects WPAdverts: from n/a through 2.3.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WPAdvertsto a version that resolves this vulnerability.Fixed in 2.3.5
Event History
Frequently Asked Questions
Which installations are affected?
WPAdverts versions through 2.3.4 are affected. The affected version range begins at an unspecified earlier version.
What does an attacker need to exploit this issue?
The vulnerability is remotely exploitable with low attack complexity and requires no privileges. It does require user interaction, consistent with a reflected XSS attack.
What is the potential impact?
Successful exploitation can affect confidentiality, integrity, and availability at low impact levels. The scope may extend beyond the vulnerable component.