HomeSecurityWPAdverts 2.3.3: Critical vulnerability in WordPress REST API

WPAdverts 2.3.3: Critical vulnerability in WordPress REST API

A high-severity vulnerability in the WPAdverts plugin for WordPress allows unauthenticated users to bypass permissions checks and read internal configuration information via the REST API . The issue is documented as CVE-2026-11801 and affects all versions up to 2.3.2.

WPAdverts 2.3.3 vulnerability in WordPress REST API

WPAdverts is used to create classifieds websites, where visitors can browse and post listings. The CVE Alert entry reports a CVSS score of 7.5 and describes an authorization bypass issue in the REST endpoint classifieds-types.

See also: Critical vulnerability in WordPress Link Library

What the WPAdverts vulnerability reveals

According to Wordfence's analysis, the endpoint does not properly verify whether the user has permission to request the data. Thus, an attacker without an account can send a request and receive information that should normally remain internal.

The data includes registered post types, their tags, associated taxonomies, form structure metadata, contact options, and custom field metadata keys. This is not necessarily a direct leak of all ad content, but the information can help identify the internal structure of a website.

The WPAdverts vulnerability is particularly significant because the attack does not require a prior login or special role in WordPress. The issue is related to access control in the application, not just a misconfiguration on a specific site. For this reason, administrators should immediately check the plugin version.

WPAdverts 2.3.3 REST API vulnerability and internal settings

The fixed version WPAdverts 2.3.3 for the REST API

Wordfence says the patched version is 2.3.3 or later. The plugin's page on the official WordPress.org lists version 2.3.3 as available since August 5, 2026, and notes that it fixed an endpoint permissions issue.

The Wordfence report lists Deva Parekh as the researcher, with a public release on August 17, 2026, and an update on August 18. This evidence links CVE-2026-11801 to a specific version rather than a vague warning for the WordPress ecosystem.

Administrators can open their WordPress dashboard and go to the installed plugins page. There, they should confirm that WPAdverts has been upgraded to version 2.3.3 or later. If automatic update is not available, it is recommended to download it only from the official plugin page and check if the upgrade was successful.

See also: Critical vulnerability in W3 Total Cache for WordPress

Unauthorized access to the WPAdverts REST API

Checks after upgrading to WPAdverts 2.3.3

After installing WPAdverts 2.3.3, administrators should check server logs for unusual requests to the REST API, and specifically to classifieds-types. The search should cover requests without a user session, repeated calls, and access from unknown IP addresses.

In addition, it is helpful to verify that security plugins, application firewall, and REST API throttling rules are working properly. These measures are not a substitute for updating, but can help limit exposure until the patch is fully deployed to all sites.

The SecNews technical team also recommends re-checking administrator accounts, removing old or unused plugins, and taking a backup before making any changes. If suspicious calls or unexpected configuration changes are detected, further investigation by the site's security officer is required.

On websites hosting a lot of ads, the plugin configuration is often associated with custom content types and taxonomies. For this reason, after the upgrade, it is necessary to check whether the forms, ads pages and contact settings work as before. The SecNews technical team recommends that the test be done first on a copy of the website, when possible.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: New pre-auth XSS in WordPress can lead to PHP execution

WPAdverts 2.3.3 update for REST API vulnerability

CVE-2026-11801 shows that even an ad plugin can expose useful information when proper authorization checks are absent. Upgrading to WPAdverts 2.3.3 or later, limiting REST API exposure, and checking log files are key immediate steps.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS