Advanced Classifieds & Directory Pro <= 3.4.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Listing Contact Fields

Medium 4.9 CWE-79Fixed in 3.5.0
ID
WPSEC-2026-0538
Plugin
Advanced Classifieds & Directory Pro (advanced-classifieds-and-directory-pro)
Affected
from 1.7.3 before 3.5.0
Remediation
Update to 3.5.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
Attack surface
Advanced Classifieds & Directory Pro on WPSec AttackSurface
Fix released
Published

Description

The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the listing contact fields in versions 1.7.3 up to, and including, 3.4.4 due to insufficient input sanitization and output escaping in the legacy listing contact template. When the 'Force bootstrap CSS' setting is enabled, the legacy template prints the listing's phone number inside a link attribute without escaping, and quotes in the value are not removed when it is saved. The setting is off on new installs but is turned on automatically for sites upgraded from versions before 3.0, and versions before 3.0 always use the legacy template. This makes it possible for authenticated attackers with subscriber-level access and above, who can submit listings from the front end by default, to inject arbitrary web scripts in listing pages that will execute whenever a user accesses an injected page.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0