Description
Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions.
Published: 2026-06-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated cross‑site scripting flaw found in the WordPress "ManageWP Worker" plugin versions up to and including 4.9.31. An attacker can embed malicious JavaScript into content that is rendered by the plugin’s administrative interface, allowing the execution of arbitrary code in the context of any user who views the affected pages. Because the flaw is not protected by authentication, it can be triggered by any visitor to the site, including unauthenticated users. The attacker’s capabilities are limited to the browser context of each user, meaning the impact primarily affects confidentiality and integrity of data accessed in the victim’s session, and could be used to steal credentials or deface the site. The Common Vulnerability Scoring System rates the issue as 7.1, indicating a high severity level. The EPSS score of less than 1% suggests a comparatively low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog.

Affected Systems

The affected product is the WordPress "ManageWP Worker" plugin from the vendor ManageWP, for all releases up to version 4.9.31. Any WordPress installation using the plugin in those versions is vulnerable and should be updated.

Risk and Exploitability

The CVSS score of 7.1 reflects the high impact of an unauthenticated XSS vulnerability. Because the attacker does not need privileged access and can exploit it via a standard web request, the risk remains significant despite the low EPSS score. The issue is not in the CISA KEV catalog, which indicates insufficient evidence of widespread exploitation yet. Potential exploitation would involve inserting script into the plugin’s admin pages and then luring users to visit those pages to execute the payload.

Generated by OpenCVE AI on June 16, 2026 at 21:13 UTC.

Remediation

Vendor Solution

Update the WordPress ManageWP Worker Plugin to the latest available version (at least 4.9.32).


OpenCVE Recommended Actions

  • Apply the latest ManageWP Worker plugin update (at least 4.9.32).
  • If an update cannot be performed immediately, temporarily deactivate the ManageWP Worker plugin to eliminate the attack surface until the fix is applied.
  • Restrict access to the plugin’s administrative interface to trusted IP addresses to reduce the exposure of the vulnerable pages.

Generated by OpenCVE AI on June 16, 2026 at 21:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Jun 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Managewp
Managewp managewp Worker
Wordpress
Wordpress wordpress
Vendors & Products Managewp
Managewp managewp Worker
Wordpress
Wordpress wordpress

Mon, 15 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions.
Title WordPress ManageWP Worker plugin <= 4.9.31 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Managewp Managewp Worker
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-16T17:12:07.093Z

Reserved: 2026-04-07T10:41:57.169Z

Link: CVE-2026-39463

cve-icon Vulnrichment

Updated: 2026-06-16T13:30:00.377Z

cve-icon NVD

Status : Deferred

Published: 2026-06-15T21:16:43.357

Modified: 2026-06-15T21:24:32.790

Link: CVE-2026-39463

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T21:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')