
WPAdverts – Classifieds Plugin Security & Risk Analysis
wordpress.org/plugins/wpadvertsBuild classifieds section in seconds. Allow your visitors to browse and post (paid or free) classified ads on your site.
Is WPAdverts – Classifieds Plugin Safe to Use in 2026?
Use With Caution
Score 62/100WPAdverts – Classifieds Plugin has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The WPAdverts plugin v2.3.0 exhibits a mixed security posture. While it demonstrates good practices in certain areas, such as using prepared statements for most SQL queries and implementing a reasonable number of nonce and capability checks, significant concerns exist regarding its attack surface and historical vulnerability patterns. The substantial number of AJAX handlers, all lacking authentication checks, represents a critical risk, potentially allowing unauthenticated users to trigger arbitrary actions within the plugin. The taint analysis, though limited in scope, identified flows with unsanitized paths, hinting at potential for insecure file operations or path traversal vulnerabilities, even without critical severity. The plugin's history of nine CVEs, with one still unpatched and a prevalence of high and medium severity issues including missing authorization, XSS, and RFI, is a strong indicator of recurring security weaknesses that require serious attention. The presence of an unpatched vulnerability, especially one with high severity, further elevates the risk profile. In conclusion, while the plugin shows some positive security engineering, the large unprotected attack surface and its past vulnerability history necessitate a cautious approach and prompt remediation of outstanding issues.
Key Concerns
- Large attack surface without auth checks (AJAX)
- Unpatched CVE (1 high severity)
- Multiple high/medium severity CVEs in history
- Flows with unsanitized paths (taint analysis)
- Output escaping not consistently applied (68%)
- Missing permission callbacks on REST API
WPAdverts – Classifieds Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
9 total CVEs
WPAdverts – Classifieds Plugin <= 2.2.11 - Missing Authorization
WPAdverts <= 2.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
WPAdverts <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
WPAdverts <= 2.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
WPAdverts <= 2.2.2 - Authenticated (Contributor+) Local File Inclusion
WPAdverts <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
WPAdverts – Classifieds Plugin <= 2.1.7 - Reflected Cross-Site Scripting
WPAdverts – Classifieds Plugin <= 2.1.6 - Unauthenticated Stored Cross-Site Scripting via adverts_add Shortcode
WPAdverts – Classifieds Plugin <= 2.1.2 - Cross-Site Request Forgery
WPAdverts – Classifieds Plugin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPAdverts – Classifieds Plugin Attack Surface
AJAX Handlers 35
REST API Routes 1
Shortcodes 7
WordPress Hooks 190
Scheduled Events 4
Maintenance & Trust
WPAdverts – Classifieds Plugin Maintenance & Trust
Maintenance Signals
Community Trust
WPAdverts – Classifieds Plugin Alternatives
Motors – Car Dealership & Classified Listings Plugin
motors-car-dealership-classified-listings
Manage classified listings with WordPress, and allow users to post classified listings directly to your website.
AWP Classifieds
another-wordpress-classifieds-plugin
Create a classified listings directory, from auto listings to yard sales with AWP Classifieds plugin.
Cleanup – Directory Listing & Classifieds WordPress Plugin
cleanup-light
Manage directory listings from both the front-end and the WordPress admin panel. Fully responsive design with an intuitive AJAX-powered interface.
Directorist: AI-Powered Business Directory, Listings & Classified Ads
directorist
Build any type of directory website such as a business directory, job directory, classifieds directory, and more with this WordPress directory plugin.
Classified Listing – AI-Powered Classified ads & Business Directory Plugin
classified-listing
A Classified ads and Business Directory plugin for WordPress, to create classified listing, real estate directory, local business directory, and more.
WPAdverts – Classifieds Plugin Developer Profile
4 plugins · 6K total installs
How We Detect WPAdverts – Classifieds Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpadverts/assets/css/wpadverts-autocomplete.css/wp-content/plugins/wpadverts/assets/css/wpadverts-upload.css/wp-content/plugins/wpadverts/assets/css/wpadverts-glyphs.css/wp-content/plugins/wpadverts/assets/css/animation.css/wp-content/plugins/wpadverts/assets/css/all.min.css/wp-content/plugins/wpadverts/assets/css/blocks.min.css/wp-content/plugins/wpadverts/assets/js/wpadverts-form.js/wp-content/plugins/wpadverts/assets/js/wpadverts-form.jswpadverts-autocompletewpadverts-uploadwpadverts-glyphsanimationall.min.cssblocks.min.csswpadverts-form.jsHTML / DOM Fingerprints
wpa-solidwpa-shadow-noneatw-font-boldatw-font-normaladverts-upload-thumbnailadverts-listadverts-gallerydata-adverts-form-idwpadverts_form_data