Description
Unauthenticated Cross Site Scripting (XSS) in Qode Music <= 2.1.8.2 versions.
Published: 2026-10-10
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross Site Scripting
Action: Patch
AI Analysis

Impact

An unauthenticated Cross Site Scripting flaw exists in Qode Music plugin versions 2.1.8.2 or earlier. The flaw allows an attacker to insert malicious JavaScript that will execute in the browsers of any visitor who loads a page rendered by the affected plugin. This can permit the attacker to manipulate page content, place hidden data on the page, or perform client‑side attacks on site users.

Affected Systems

WordPress sites that have the Qode Music plugin version 2.1.8.2 or earlier. The plugin is distributed by the vendor QODE and is commonly used to display music content within WordPress themes.

Risk and Exploitability

The CVSS score of 7.1 classifies the vulnerability as moderate‑to‑high severity. The EPSS score is not provided and the issue is not listed in CISA’s KEV catalog, so it is unclear how often it is actively exploited. Nonetheless, the flaw is completely unauthenticated; any user able to view the vulnerable page can craft a payload that will run in the browsers of other visitors.

Generated by OpenCVE AI on October 10, 2026 at 21:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Qode Music plugin to the latest version that includes the XSS fix.
  • Disable or uninstall the Qode Music plugin until an update becomes available.
  • Inspect the site’s content for injected scripts or defacement and remove any malicious elements found.

Generated by OpenCVE AI on October 10, 2026 at 21:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Qode Music <= 2.1.8.2 versions.
Title WordPress Qode Music plugin <= 2.1.8.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T19:37:16.514Z

Reserved: 2026-04-29T07:06:45.122Z

Link: CVE-2026-42631

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T20:16:34.837

Modified: 2026-10-10T20:16:34.837

Link: CVE-2026-42631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T21:15:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')