← back

CVE-2026-57366

HIGH · 7.1 EPSS 0.2%
hype MOSTLY HYPE · 18 hack

Recycled identical posts, no PoC, no advisory, baseline vendor announcement echo.

What: Unauthenticated Cross-Site Scripting (XSS) in WPAdverts WordPress plugin ≤2.3.1 (CVSS 7.1, HIGH).

Why it matters: No KEV listing, no public PoC referenced in posts, no vendor advisory evidence provided. Low EPSS (0.0904th percentile) suggests minimal observed exploitation signals. Chatter is identical boilerplate repeated across 8 posts with no actionable detail—hashtag spam ("proofofconcept") without substantive analysis or exploit demonstration.

Where it's seen: Pure social amplification on Bluesky: eight identical posts mentioning the CVE ID and plugin name with generic cybersecurity hashtags. No researcher commentary, no plugin update advisory links, no defender triage signals.

RISK: MODERATE — HIGH CVSS but unpatched plugin with XSS; low EPSS and no KEV listing temper urgency.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 7/23/2026, 5:23:08 PM

Description

Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.1 versions.

CVSS 3.1 breakdown

Exploitability 2.8 · Impact 3.7
vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack vector
Network
Complexity
Low
Privileges required
None
User interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low

Weaknesses