Description
The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Published: 2026-05-27
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The rexCrawler plugin contains a stored cross‑site scripting flaw in all released versions through 1.0.15. An attacker who is authenticated with administrator‑level permissions can place arbitrary JavaScript into an admin settings field because the input is neither sanitized nor escaped properly. When the setting value is later rendered on a page accessed by other users, the injected script executes in their browser, allowing the attacker to steal credentials, deface the site, or redirect traffic. This vulnerability is a classic example of CWE‑79 and is limited to WordPress multi‑site installations or sites that have disabled the unfiltered_html capability.

Affected Systems

WordPress sites using the rexCrawler plugin at any version up to and including 1.0.15 are affected. The flaw only manifests on multi‑site installs or on single‑site installs where the unfiltered_html capability has been turned off. Exploitation requires that the attacker have administrator or higher privileges within the WordPress instance.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity. The EPSS score is not available, but once the attacker gains legitimate administrator access—potentially via a compromised site owner—the stored script remains until the settings are manually cleared, providing persistent client‑side compromise. The vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known sophisticated exploits. The attack path requires only routine admin login, navigation to the rexCrawler settings, injection of malicious script, and subsequent visitation of the affected page by other users. Overall, this poses a moderate risk of cross‑site compromise for users of vulnerable WordPress deployments.

Generated by OpenCVE AI on May 27, 2026 at 11:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade rexCrawler to the latest version that removes the stored XSS flaw
  • If a patch cannot be applied immediately, disable or delete the rexCrawler plugin from the site
  • Restrict the unfiltered_html capability for administrators or enforce stricter input sanitization on the plugin’s settings

Generated by OpenCVE AI on May 27, 2026 at 11:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 27 May 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Larsdrasmussen
Larsdrasmussen rexcrawler
Wordpress
Wordpress wordpress
Vendors & Products Larsdrasmussen
Larsdrasmussen rexcrawler
Wordpress
Wordpress wordpress

Wed, 27 May 2026 10:30:00 +0000

Type Values Removed Values Added
Description The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Title rexCrawler <= 1.0.15 - Authenticated (Administrator+) Stored Cross-Site Scripting via Settings
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Larsdrasmussen Rexcrawler
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-05-27T09:27:30.880Z

Reserved: 2026-02-10T14:16:27.618Z

Link: CVE-2026-2280

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-27T11:16:17.873

Modified: 2026-05-27T11:16:17.873

Link: CVE-2026-2280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T12:00:32Z

Weaknesses