Description
Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
Published: 2026-08-06
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic Cross Site Scripting flaw that allows any user to inject malicious scripts into the WordPress WPIDE – File Manager & Code Editor plugin. This flaw is identified as CWE‑79 and could be used by an attacker to deface the site, steal session cookies, or perform other browser‑based attacks. The vulnerability is unauthenticated, meaning it can be leveraged by anyone who can load the plugin interface.

Affected Systems

The affected product is XplodedThemes’ WPIDE – File Manager & Code Editor plugin for WordPress, with all releases up to and including version 3.5.7. Users running these versions are at risk, while versions 3.5.8 and later contain the fix.

Risk and Exploitability

The CVSS score of 7.1 classifies this issue as a high‑severity flaw. EPSS is not available, but the lack of a KEV listing suggests it is not yet commonly exploited. The attack vector is inferred to be any user who can load the plugin, implying that the vulnerability is exploitable without special permissions.

Generated by OpenCVE AI on August 6, 2026 at 15:39 UTC.

Remediation

Vendor Solution

Update the WordPress WPIDE – File Manager & Code Editor Plugin to the latest available version (at least 3.5.8).


OpenCVE Recommended Actions

  • Update the WordPress WPIDE – File Manager & Code Editor Plugin to at least 3.5.8
  • If an immediate update is not possible, disable the plugin to eliminate the attack surface
  • Review and remove any residual code‑editing or file‑manager plugins that may still contain similar XSS weaknesses

Generated by OpenCVE AI on August 6, 2026 at 15:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Xplodedthemes
Xplodedthemes wpide - File Manager & Code Editor
Vendors & Products Wordpress
Wordpress wordpress
Xplodedthemes
Xplodedthemes wpide - File Manager & Code Editor

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
Title WordPress WPIDE – File Manager & Code Editor plugin <= 3.5.7 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Xplodedthemes Wpide - File Manager & Code Editor
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:27:49.979Z

Reserved: 2026-07-27T09:00:18.436Z

Link: CVE-2026-66440

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T17:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')