Stored Cross-Site Scripting Vulnerability in WPAdverts Classifieds Plugin
CVE-2026-100178

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 October 2026

What is CVE-2026-100178?

The WPAdverts - Classifieds Plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) through the 'adverts_location' parameter due to inadequate input sanitization and output escaping. This vulnerability permits unauthorized attackers to inject malicious web scripts, which may execute when users access affected pages, potentially compromising user data and site integrity.

Affected Version(s)

WPAdverts – Classifieds Plugin 0 <= 2.3.4

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Morato Antoine
.