Executive brief
WPAdverts is a WordPress plugin used to create and manage classified ads on websites. A security flaw in versions 2.3.0 and earlier allows unauthorized individuals to perform actions that should be restricted to administrators or site owners. This could lead to unauthorized changes to advertisements or site settings, potentially disrupting business operations and the integrity of the classifieds platform.
Technical details
A broken access control vulnerability exists in the WPAdverts plugin for WordPress due to missing authorization checks (CWE-862). The flaw allows an unauthenticated remote attacker to execute functions or actions that should require higher privileges. Based on the CVSS vector, the impact is limited to partial loss of integrity and availability, without direct data confidentiality risks. The vulnerability is exploitable over the network without user interaction. Users should update to version 2.3.1 or later to remediate the issue.
Affected products
- WPAdverts WPAdverts <= 2.3.0
Timeline
- 2026-03-12: other: Reported by TheNetRunner Security Research
- 2026-04-22: advisory: Initial advisory published by Patchstack
- 2026-06-15: disclosed: NVD publication date