PatchSiren cyber security CVE debrief
CVE-2026-93883 pluginsware CVE debrief
The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone' parameter in all versions up to, and including, 3.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Vendor
- pluginsware
- Product
- Advanced Classifieds & Directory Pro
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for WordPress sites using the Advanced Classifieds & Directory Pro plugin should assess exposure and prioritize verification of their sites' configurations and plugin versions.
Why it matters
CVE-2026-93883 is a Stored Cross-Site Scripting vulnerability in the Advanced Classifieds & Directory Pro plugin for WordPress. It allows authenticated attackers with custom-level access to inject arbitrary web scripts via the 'phone' parameter, which can execute on page access. This vulnerability requires specific conditions to be met, including the 'Force Bootstrap' setting being enabled and the 'ACADP Listing Address' widget being used on single listing pages. Defenders should verify their sites' exposure, prioritize patching or mitigating the vulnerability, and monitor for suspicious activity.
- Defenders need to verify if their sites are using version 3.4.4 or lower of the plugin and have the conditions for exploitation met.
- Sites with the 'Force Bootstrap' setting enabled and the 'ACADP Listing Address' widget on single listing pages are potentially vulnerable.
- Successful exploitation could allow authenticated attackers to inject malicious scripts, potentially leading to user interactions with injected content.
- Defenders should prioritize updating to a patched version of the plugin if available and consider compensating controls like limiting plugin functionality or closely monitoring site activity.
Technical summary
The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone' parameter in all versions up to, and including, 3.4.4. This is due to insufficient input sanitization and output escaping. An attacker with custom-level access and above can inject arbitrary web scripts that will execute when a user accesses an injected page. This vulnerability is only exploitable if the 'Force Bootstrap' setting is enabled and the 'ACADP Listing Address' widget is used on single listing pages.
Defensive priority
Defenders should prioritize verifying if their sites use the affected plugin version and have the 'Force Bootstrap' setting enabled, and assess exposure based on the presence of the 'ACADP Listing Address' widget on single listing pages.
Recommended defensive actions
- Verify if the Advanced Classifieds & Directory Pro plugin version is 3.4.4 or lower and update to a patched version if available.
- Check if the 'Force Bootstrap' miscellaneous setting is enabled and consider disabling it if not necessary.
- Assess the presence of the 'ACADP Listing Address' widget on single listing pages and consider removing it if not necessary.
- Monitor for any suspicious activity related to the plugin and the 'phone' parameter.
- Perform a thorough review of the plugin's configuration and usage to identify potential vulnerabilities.
- Implement additional security measures such as Web Application Firewall (WAF) rules to detect and prevent exploitation.
- Keep records of the verification and mitigation efforts for future reference and auditing purposes.
Evidence notes
The CVE record and source item provide details on the vulnerability, including its existence in versions up to 3.4.4 of the Advanced Classifieds & Directory Pro plugin and the specific conditions under which it can be exploited.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-93883 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-93883
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-93883 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93883
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Advanced Classifieds & Directory Pro <= 3.4.4 - Authenticated (Custom+) Stored Cross-Site Script
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93883.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/advanced-classifieds-and-directory-pro/tags/3.4.4/includes/helpers/html.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/advanced-classifieds-and-directory-pro/tags/3.4.4/public/user.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3728695/advanced-classifieds-and-directory-pro/trunk/includes/helpers/html.php
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.