Description
The Content Mask WordPress plugin before 1.8.5.6 does not properly sanitise and escape content submitted with a post before outputting it in the pages it generates, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks against any user viewing or previewing the affected page.
The Content Mask WordPress plugin before 1.8.5.6's option to restrict its use by role does not prevent this.
Published: 2026-09-09
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The Content Mask WordPress plugin fails to sanitize or escape content submitted in posts before rendering it on the generated pages. A user with contributor level can inject malicious script into the post, which will then be executed in the browser of any user viewing or previewing that page. This stored cross‑site scripting allows the attacker to steal session cookies, hijack user accounts, deface content, or redirect users to phishing sites.

Affected Systems

WordPress sites using the Content Mask plugin, version 1.7.1 through 1.8.5.5. Any installation of these releases is vulnerable regardless of role‑based restriction settings.

Risk and Exploitability

The vulnerability can be exploited simply by submitting a post containing a malicious payload; no special network access or external interaction is required beyond having contributor privileges. The EPSS score is 0.00163, which indicates a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. Nevertheless, the nature of stored XSS implies a high potential for exploitation on sites that are publicly accessible or used by many users. Sites that allow many contributors or lack strict content validation will be at the greatest risk. The CVSS score of 6.8 reflects a medium severity level.

Generated by OpenCVE AI on September 9, 2026 at 19:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Content Mask plugin to version 1.8.5.6 or later, which implements proper input sanitization.
  • If an upgrade is not feasible, restrict post creation and editing to administrators only, or disable the post scripts and styles feature for all other roles.
  • Deploy a Content Security Policy that blocks inline scripts and disallows execution of arbitrary script tags to mitigate any accidental remaining XSS exposure.

Generated by OpenCVE AI on September 9, 2026 at 19:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 09 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Content Mask WordPress plugin before 1.8.5.6 does not properly sanitise and escape content submitted with a post before outputting it in the pages it generates, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks against any user viewing or previewing the affected page. The Content Mask WordPress plugin before 1.8.5.6's option to restrict its use by role does not prevent this.
Title Content Mask 1.7.1 - 1.8.5.5 - Contributor+ Stored XSS via Post Scripts and Styles
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-09T15:41:36.867Z

Reserved: 2026-08-20T07:32:04.074Z

Link: CVE-2025-15690

cve-icon Vulnrichment

Updated: 2026-09-09T15:35:38.151Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T06:17:13.870

Modified: 2026-09-09T16:17:00.080

Link: CVE-2025-15690

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T19:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')