Unprotected URL Vulnerability Affects WPAdverts Classifieds Plugin
CVE-2024-10890
6.1MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 21 November 2024
What is CVE-2024-10890?
The WPAdverts - Classifieds Plugin for WordPress is susceptible to a reflected cross-site scripting issue. This vulnerability arises from inadequate input sanitization when using the add_query_arg and remove_query_arg functions on URLs. Attackers can exploit this flaw to inject malicious web scripts that execute upon user interaction, such as clicking a misleading link. The vulnerability is present in all versions prior to and including 2.1.7, which may potentially compromise the security of affected sites if users are tricked into following harmful URLs.
Affected Version(s)
WPAdverts – Classifieds Plugin * <= 2.1.7