Unprotected URL Vulnerability Affects WPAdverts Classifieds Plugin
CVE-2024-10890

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
21 November 2024

Summary

The WPAdverts - Classifieds Plugin for WordPress is susceptible to a reflected cross-site scripting issue. This vulnerability arises from inadequate input sanitization when using the add_query_arg and remove_query_arg functions on URLs. Attackers can exploit this flaw to inject malicious web scripts that execute upon user interaction, such as clicking a misleading link. The vulnerability is present in all versions prior to and including 2.1.7, which may potentially compromise the security of affected sites if users are tricked into following harmful URLs.

Affected Version(s)

WPAdverts – Classifieds Plugin * <= 2.1.7

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Thaleikis
.