{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wpadverts--classifieds-plugin--2.3.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wpadverts:classifieds_plugin:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-100178"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WPAdverts – Classifieds Plugin (\u003c= 2.3.4)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress"],"_cs_type":"advisory","_cs_vendors":["WPAdverts"],"content_html":"\u003cp\u003eThe WPAdverts - Classifieds Plugin for WordPress is affected by a stored cross-site scripting (XSS) vulnerability, tracked as CVE-2026-100178. The vulnerability exists in versions up to and including 2.3.4 and stems from insufficient input sanitization and output escaping on the 'adverts_location' parameter. This flaw allows an unauthenticated attacker to inject arbitrary web scripts into the plugin's classifieds listings. These scripts are subsequently executed in the browser of any user, including administrators, who views the compromised page. This poses a significant risk for session hijacking, unauthorized actions performed on behalf of authenticated users, or the redirection of visitors to malicious sites. Defenders should prioritize updating to the latest secure version of the plugin as soon as it becomes available to mitigate this injection risk.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a WordPress site utilizing a vulnerable version of the WPAdverts plugin.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts an HTTP request containing malicious JavaScript payloads within the 'adverts_location' parameter.\u003c/li\u003e\n\u003cli\u003eThe attacker submits this request to the application, exploiting the lack of input sanitization in the plugin's endpoint.\u003c/li\u003e\n\u003cli\u003eThe malicious script is stored directly in the WordPress database associated with the classifieds advertisement.\u003c/li\u003e\n\u003cli\u003eAn unsuspecting user, such as a site administrator or visitor, navigates to the compromised advertisement page.\u003c/li\u003e\n\u003cli\u003eThe web server renders the stored payload within the victim's browser session.\u003c/li\u003e\n\u003cli\u003eThe browser executes the injected script with the permissions of the victim's active session.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves their objective, such as session token theft or unauthorized administrative actions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this stored XSS vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the context of other users' sessions. This can lead to account takeover, unauthorized modification of site content, or the distribution of further malicious content to site visitors. Given the nature of WordPress plugins, this vulnerability affects any site running version 2.3.4 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpdate the WPAdverts - Classifieds Plugin to the latest version released after 2.3.4 to ensure the 'adverts_location' parameter is properly sanitized.\u003c/li\u003e\n\u003cli\u003eImplement a Content Security Policy (CSP) to restrict the execution of unauthorized inline scripts as a defense-in-depth measure.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for HTTP requests containing suspicious script tags or JavaScript event handlers (e.g., onerror, onload) targeting the URL structure associated with WPAdverts.\u003c/li\u003e\n\u003cli\u003ePerform a security review of site plugins and disable those that have not received recent security updates or are no longer maintained.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-10T09:51:20Z","date_published":"2026-10-10T09:51:20Z","id":"https://feed.craftedsignal.io/briefs/2026-10-wpadverts-xss/","summary":"The WPAdverts plugin for WordPress contains a stored XSS vulnerability (CVE-2026-100178) that allows unauthenticated attackers to inject malicious scripts via the 'adverts_location' parameter.","title":"Stored Cross-Site Scripting in WPAdverts Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-wpadverts-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - WPAdverts – Classifieds Plugin (\u003c= 2.3.4)","version":"https://jsonfeed.org/version/1.1"}