Description
The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<textarea_code field id> (e.g. kl_code, kl_post_code)' parameter in all versions up to, and including, 2.13.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The front-end save path requires only a CMB2 box nonce, which is emitted to all visitors including unauthenticated guests via a simple GET request, making the attack trivially reachable without any credentials on sites that expose a public CMB2 form writing a textarea_code field.
Published: 2026-10-02
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

The CMB2 WordPress plugin contains a stored cross‑site scripting flaw in the textarea_code field. The code accepts input from an unauthenticated guest, stores it without proper sanitization or escaping, and later renders it in post or page output. Thus attackers can inject arbitrary JavaScript that will execute whenever a visitor views the affected page.

Affected Systems

The vulnerability affects CMB2 versions 2.13.1 and earlier. WordPress sites that host a public CMB2 form allowing a textarea_code field are at risk. Any visitor can trigger the front‑end save because the required nonce is publicly available.

Risk and Exploitability

The CVSS base score is 7.2, indicating a high‑severity vulnerability. The exploitation probability EPSS is not available, and the vulnerability is not yet listed in the CISA KEV catalog. Because the attack vector does not require authentication and only a public nonce is needed, the likelihood of exploitation is high in practice. Attackers can inject scripts that run in the context of any user who views the compromised content, leading to defacement, credential theft or drive‑by infections.

Generated by OpenCVE AI on October 2, 2026 at 08:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update CMB2 to the latest version (greater than 2.13.1) which includes proper input sanitization.
  • Restrict the front‑end form so that only authenticated users or administrators can submit data, ensuring the nonce is not publicly accessible.
  • Manually sanitize and escape textarea_code values by applying esc_textarea() or wp_kses() before storage, or configure CMB2 to use a validated callback.

Generated by OpenCVE AI on October 2, 2026 at 08:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Description The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<textarea_code field id> (e.g. kl_code, kl_post_code)' parameter in all versions up to, and including, 2.13.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The front-end save path requires only a CMB2 box nonce, which is emitted to all visitors including unauthenticated guests via a simple GET request, making the attack trivially reachable without any credentials on sites that expose a public CMB2 form writing a textarea_code field.
Title CMB2 <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'textarea_code' Field
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T07:39:22.836Z

Reserved: 2026-09-29T16:39:17.455Z

Link: CVE-2026-102772

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T08:17:00.047

Modified: 2026-10-02T08:17:00.047

Link: CVE-2026-102772

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T08:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')