Unprotected URL Vulnerability Affects WPAdverts Classifieds Plugin
CVE-2024-10890
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 21 November 2024
What is CVE-2024-10890?
The WPAdverts - Classifieds Plugin for WordPress is susceptible to a reflected cross-site scripting issue. This vulnerability arises from inadequate input sanitization when using the add_query_arg and remove_query_arg functions on URLs. Attackers can exploit this flaw to inject malicious web scripts that execute upon user interaction, such as clicking a misleading link. The vulnerability is present in all versions prior to and including 2.1.7, which may potentially compromise the security of affected sites if users are tricked into following harmful URLs.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WPAdverts β Classifieds Plugin * <= 2.1.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved