Junglewise Threat Intelligence

CVE-2026-57366: Greg Winiarski WPAdverts unauthenticated XSS

CVE-2026-57366 · Severity: high · CVSS 7.1 · Published 2026-07-02

Technologies: Greg Winiarski WPAdverts.

Executive brief

WPAdverts, a popular WordPress plugin used for creating classified ads, contains a security flaw that allows unauthorized individuals to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, an attacker could potentially hijack user sessions, redirect visitors to malicious websites, or deface the site. This could lead to a loss of customer trust and potential data theft from users interacting with the ads platform.

Technical details

The WPAdverts plugin for WordPress is vulnerable to Unauthenticated Reflected Cross-Site Scripting (XSS) in versions up to 2.3.1 due to improper neutralization of user-supplied input (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted page. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized actions. The vulnerability is addressed in version 2.3.2.

Affected products

  • Greg Winiarski WPAdverts <= 2.3.1

Timeline

  • 2026-05-08: other: Vulnerability reported by Evan NR
  • 2026-07-01: advisory: Patchstack published advisory
  • 2026-07-02: disclosed: NVD published CVE-2026-57366
  • 2026-07-02: patched: Version 2.3.2 released to address the issue

References