{
 "id": "WPSEC-2026-0538",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0538/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0538/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0538/index.md",
 "title": "Advanced Classifieds & Directory Pro <= 3.4.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Listing Contact Fields",
 "description": "The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the listing contact fields in versions 1.7.3 up to, and including, 3.4.4 due to insufficient input sanitization and output escaping in the legacy listing contact template. When the 'Force bootstrap CSS' setting is enabled, the legacy template prints the listing's phone number inside a link attribute without escaping, and quotes in the value are not removed when it is saved. The setting is off on new installs but is turned on automatically for sites upgraded from versions before 3.0, and versions before 3.0 always use the legacy template. This makes it possible for authenticated attackers with subscriber-level access and above, who can submit listings from the front end by default, to inject arbitrary web scripts in listing pages that will execute whenever a user accesses an injected page.",
 "plugin": {
  "slug": "advanced-classifieds-and-directory-pro",
  "name": "Advanced Classifieds & Directory Pro",
  "full_name": "Advanced Classifieds & Directory Pro",
  "wordpress_org": "https://wordpress.org/plugins/advanced-classifieds-and-directory-pro/",
  "advisories_url": "https://wpsec.com/vuln/plugin/advanced-classifieds-and-directory-pro/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/advanced-classifieds-and-directory-pro"
 },
 "type": "XSS",
 "cwe": [
  "CWE-79"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.9,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "1.7.3",
    "from_inclusive": true,
    "to": "3.5.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 1.7.3 before 3.5.0"
  ]
 },
 "introduced_in": "1.7.3",
 "fixed_in": "3.5.0",
 "remediation": "Update to 3.5.0 or later.",
 "fix_released": "2026-10-05T10:47:33+00:00",
 "published": "2026-10-07T12:46:23+00:00",
 "updated": "2026-10-07T12:35:01.590273+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0538/",
  "https://plugins.svn.wordpress.org/advanced-classifieds-and-directory-pro/tags/3.5.0/",
  "https://wordpress.org/plugins/advanced-classifieds-and-directory-pro/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/advanced-classifieds-and-directory-pro",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-07"
 }
}