CVE-2026-57366
HIGH · 7.1 EPSS 0.2%Recycled identical posts, no PoC, no advisory, baseline vendor announcement echo.
What: Unauthenticated Cross-Site Scripting (XSS) in WPAdverts WordPress plugin ≤2.3.1 (CVSS 7.1, HIGH).
Why it matters: No KEV listing, no public PoC referenced in posts, no vendor advisory evidence provided. Low EPSS (0.0904th percentile) suggests minimal observed exploitation signals. Chatter is identical boilerplate repeated across 8 posts with no actionable detail—hashtag spam ("proofofconcept") without substantive analysis or exploit demonstration.
Where it's seen: Pure social amplification on Bluesky: eight identical posts mentioning the CVE ID and plugin name with generic cybersecurity hashtags. No researcher commentary, no plugin update advisory links, no defender triage signals.
RISK: MODERATE — HIGH CVSS but unpatched plugin with XSS; low EPSS and no KEV listing temper urgency.
Description
Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.1 versions.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L- Attack vector
- Network
- Complexity
- Low
- Privileges required
- None
- User interaction
- Required
- Scope
- Changed
- Confidentiality
- Low
- Integrity
- Low
- Availability
- Low