Description
Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions.
Published: 2026-10-01
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross Site Scripting (XSS)
Action: Immediate Patch
AI Analysis

Impact

Unauthenticated Cross Site Scripting (XSS) exists in the WordPress Parallax Section Block plugin versions 2.0.4 and earlier. The flaw arises when the plugin fails to properly sanitize user‑supplied input that is rendered in the page. As a result, an attacker can inject arbitrary scripts that execute in the browsers of visitors who view affected content, potentially leading to session hijacking, credential theft, or defacement. The vulnerability is a classic example of CWE‑79, implying both confidentiality and integrity risks if exploited.

Affected Systems

Affected systems are WordPress sites that have the bPlugins Parallax Section Block plugin installed at any version up to and including 2.0.4. No other WordPress components or plugins are explicitly listed as vulnerable. Site owners should verify the installed version of this plugin and apply the recommended update.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, and the flaw is exploitable without authentication, making the risk substantial. EPSS data is not available, and the vulnerability has not been listed in the CISA KEV catalog, suggesting no known large‑scale exploitation at this time. However, the lack of required credentials and the native cross‑site execution path make it a prime target for automated attacks, warranting immediate attention.

Generated by OpenCVE AI on October 1, 2026 at 15:22 UTC.

Remediation

Vendor Solution

Update the WordPress Parallax Section - Block plugin to the latest available version (at least 2.1.0).


OpenCVE Recommended Actions

  • Update the WordPress Parallax Section Block plugin to version 2.1.0 or later.
  • If an update cannot be applied immediately, deactivate or uninstall the plugin to eliminate the vulnerable functionality until a patch is available.
  • Implement site‑wide XSS protection, such as adding Content‑Security‑Policy headers and configuring a security plugin to sanitize and escape user input throughout the site.

Generated by OpenCVE AI on October 1, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions.
Title WordPress Parallax Section block plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-01T14:57:37.004Z

Reserved: 2026-09-29T00:15:56.341Z

Link: CVE-2026-102378

cve-icon Vulnrichment

Updated: 2026-10-01T14:57:14.875Z

cve-icon NVD

Status : Received

Published: 2026-10-01T15:17:25.727

Modified: 2026-10-01T15:17:25.727

Link: CVE-2026-102378

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')