Description
The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Published: 2026-06-02
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The rognone WordPress plugin contains an input handling flaw that allows an unauthenticated attacker to inject arbitrary JavaScript by supplying a crafted value to the "mode" parameter. Because the plugin does not correctly sanitize or escape this input, any victim who follows a specially constructed link will have the malicious script executed in their browser. This can lead to script‑based data theft, session hijacking, or defacement of the affected site. The weakness corresponds to CWE‑79, which highlights improper input validation and insufficient output encoding.

Affected Systems

The vulnerability affects the rognone plugin developed by federicocarrara, specifically versions up to and including 0.6.2 deployed on WordPress sites. Sites running an older rognone version are vulnerable by default.

Risk and Exploitability

The CVSS score of 6.1 indicates a medium impact. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this flaw by simply including the malicious "mode" parameter in a URL and convincing a legitimate user to click it, without any authentication or advanced privilege. Because the plugin is widely used, the attack surface is substantial.

Generated by OpenCVE AI on June 2, 2026 at 09:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the rognone plugin to a version newer than 0.6.2 or remove the plugin entirely if it is not needed.
  • If an update is not immediately possible, disable the rognone plugin or restrict its access through firewall or role restrictions to prevent unauthenticated users from reaching the vulnerable endpoint.
  • Configure a robust content security policy to restrict script execution and mitigate the impact of potential future XSS attempts.

Generated by OpenCVE AI on June 2, 2026 at 09:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Federicocarrara
Federicocarrara rognone
Wordpress
Wordpress wordpress
Vendors & Products Federicocarrara
Federicocarrara rognone
Wordpress
Wordpress wordpress

Tue, 02 Jun 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Jun 2026 08:30:00 +0000

Type Values Removed Values Added
Description The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Title rognone <= 0.6.2 - Reflected Cross-Site Scripting via 'mode' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Federicocarrara Rognone
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-06-02T10:46:38.177Z

Reserved: 2026-01-26T17:54:51.241Z

Link: CVE-2026-1450

cve-icon Vulnrichment

Updated: 2026-06-02T10:46:33.161Z

cve-icon NVD

Status : Deferred

Published: 2026-06-02T09:16:15.430

Modified: 2026-06-02T13:03:31.153

Link: CVE-2026-1450

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T20:52:02Z

Weaknesses