← WordPress Vulnerabilities
WordPress security by component

WPAdverts – Classifieds Plugin

WPAdverts – Classifieds Plugin creates classified advertisement listings with categories, search, front-end submissions, and listing management in WordPress.

WPAdverts – Classifieds Plugin (wpadverts) is a WordPress plugin with 13 published CVE records in this archive. The latest tracked vulnerability was published Sep 10, 2026; the highest published CVSS base score is 7.5.

Plugin slug: wpadverts

CVE-2026-84819: WPAdverts permits unauthenticated cross-site scripting

WPAdverts through 2.3.3 has a cross-site scripting flaw reachable without an account. Attacker-controlled script can execute in a victim's browser; the CNA vector requires user interaction and rates confidentiality, integrity, and availability impacts as low.

PublishedSep 10, 2026
Known safe version2.3.4
Published vulnerabilities for wpadverts
Safe version
Sep 10, 2026 CVE-2026-84819
WPAdverts permits unauthenticated cross-site scripting
WPAdverts through 2.3.3 has a cross-site scripting flaw reachable without an account. Attacker-controlled script can execute in a victim's browser; the CNA vector requires user interaction and rates confidentiality, integrity, and availability impacts as low.
2.3.4
CVE7.1
NVDPending
Aug 18, 2026 CVE-2026-11801
WPAdverts classifieds-types REST endpoint exposes internal configuration
WPAdverts through 2.3.2 exposes its classifieds-types REST endpoint without adequate authorization. An unauthenticated request can retrieve internal site configuration including registered post types and labels, associated taxonomies, form-scheme metadata, contact options and custom-field meta keys.
2.3.3
CVE7.5
NVDPending
Jul 02, 2026 CVE-2026-57366
WPAdverts: Cross-site scripting
WPAdverts is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.3.1.
2.3.2
CVE7.1
NVDPending
Jun 15, 2026 CVE-2026-40782
WPAdverts: Broken access control
WPAdverts is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 2.3.0.
2.3.1
CVE6.5
NVDPending
Feb 19, 2026 CVE-2026-27092
WPAdverts: A security weakness
WPAdverts is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Jul 16, 2025 CVE-2025-54024
WPAdverts: Cross-site scripting
WPAdverts is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Jun 17, 2025 CVE-2025-49878
WPAdverts: Cross-site scripting
WPAdverts is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
May 19, 2025 CVE-2025-48269
WPAdverts: Cross-site scripting
WPAdverts is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
May 07, 2025 CVE-2025-47440
WPAdverts: Filesystem traversal
WPAdverts is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Apr 16, 2025 CVE-2025-39576
WPAdverts: Cross-site scripting
WPAdverts is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Jan 02, 2025 CVE-2024-37238
WPAdverts: Cross-site request forgery
WPAdverts is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Nov 21, 2024 CVE-2024-10890
WPAdverts – Classifieds Plugin: Cross-site scripting
WPAdverts – Classifieds Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Oct 30, 2024 CVE-2024-10108
WPAdverts – Classifieds Plugin: Cross-site scripting
WPAdverts – Classifieds Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVDPending