# Advanced Classifieds & Directory Pro <= 3.4.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Listing Contact Fields

- **ID:** WPSEC-2026-0538
- **Plugin:** Advanced Classifieds & Directory Pro (`advanced-classifieds-and-directory-pro`), https://wordpress.org/plugins/advanced-classifieds-and-directory-pro/
- **Affected versions:** from 1.7.3 before 3.5.0
- **Fixed in:** 3.5.0 (Update to 3.5.0 or later.)
- **Severity:** Medium 4.9 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/advanced-classifieds-and-directory-pro
- **Fix released:** 2026-10-05
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0538/

## Description

The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the listing contact fields in versions 1.7.3 up to, and including, 3.4.4 due to insufficient input sanitization and output escaping in the legacy listing contact template. When the 'Force bootstrap CSS' setting is enabled, the legacy template prints the listing's phone number inside a link attribute without escaping, and quotes in the value are not removed when it is saved. The setting is off on new installs but is turned on automatically for sites upgraded from versions before 3.0, and versions before 3.0 always use the legacy template. This makes it possible for authenticated attackers with subscriber-level access and above, who can submit listings from the front end by default, to inject arbitrary web scripts in listing pages that will execute whenever a user accesses an injected page.

## References

- https://wpsec.com/vuln/WPSEC-2026-0538/
- https://plugins.svn.wordpress.org/advanced-classifieds-and-directory-pro/tags/3.5.0/
- https://wordpress.org/plugins/advanced-classifieds-and-directory-pro/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0538/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
