Stored Cross-Site Scripting in WPAdverts Plugin
The WPAdverts plugin for WordPress contains a stored XSS vulnerability (CVE-2026-100178) that allows unauthenticated attackers to inject malicious scripts via the 'adverts_location' parameter.
CVE search metadata
CVE search record: CVE-2026-100178. Severity: high. CVSS: 7.2. KEV: no. Product: WPAdverts – Classifieds Plugin (<= 2.3.4). Brief: Stored Cross-Site Scripting in WPAdverts Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-wpadverts-xss/
The WPAdverts - Classifieds Plugin for WordPress is affected by a stored cross-site scripting (XSS) vulnerability, tracked as CVE-2026-100178. The vulnerability exists in versions up to and including 2.3.4 and stems from insufficient input sanitization and output escaping on the 'adverts_location' parameter. This flaw allows an unauthenticated attacker to inject arbitrary web scripts into the plugin's classifieds listings. These scripts are subsequently executed in the browser of any user, including administrators, who views the compromised page. This poses a significant risk for session hijacking, unauthorized actions performed on behalf of authenticated users, or the redirection of visitors to malicious sites. Defenders should prioritize updating to the latest secure version of the plugin as soon as it becomes available to mitigate this injection risk.
Attack Chain
- An unauthenticated attacker identifies a WordPress site utilizing a vulnerable version of the WPAdverts plugin.
- The attacker crafts an HTTP request containing malicious JavaScript payloads within the 'adverts_location' parameter.
- The attacker submits this request to the application, exploiting the lack of input sanitization in the plugin's endpoint.
- The malicious script is stored directly in the WordPress database associated with the classifieds advertisement.
- An unsuspecting user, such as a site administrator or visitor, navigates to the compromised advertisement page.
- The web server renders the stored payload within the victim's browser session.
- The browser executes the injected script with the permissions of the victim's active session.
- The attacker achieves their objective, such as session token theft or unauthorized administrative actions.
Impact
Successful exploitation of this stored XSS vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the context of other users' sessions. This can lead to account takeover, unauthorized modification of site content, or the distribution of further malicious content to site visitors. Given the nature of WordPress plugins, this vulnerability affects any site running version 2.3.4 or earlier.
Recommendation
- Update the WPAdverts - Classifieds Plugin to the latest version released after 2.3.4 to ensure the 'adverts_location' parameter is properly sanitized.
- Implement a Content Security Policy (CSP) to restrict the execution of unauthorized inline scripts as a defense-in-depth measure.
- Monitor web server logs for HTTP requests containing suspicious script tags or JavaScript event handlers (e.g., onerror, onload) targeting the URL structure associated with WPAdverts.
- Perform a security review of site plugins and disable those that have not received recent security updates or are no longer maintained.
Immediate actions
Update WPAdverts to latest version
Mitigations
Upgrade WPAdverts to version above 2.3.4
CVE-2026-100178