Description
Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.
Published: 2026-09-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting
Action: Immediate Patch
AI Analysis

Impact

A Cross Site Scripting vulnerability exists in the PublishPress Series WordPress plugin for versions 3.1.3 and earlier. The flaw allows a contributor user to inject arbitrary JavaScript or HTML into posts or series metadata. Because the input is rendered without proper escaping, an attacker can execute code in the context of any visitor to the site, enabling session hijacking, defacement, or redirection. The issue maps to CWE-79 and was scored with a CVSS base of 6.5 by the CNA.

Affected Systems

The affected product is PublishPress Series plugin for WordPress, with all releases through version 3.1.3. Site administrators should check the active plugin version and confirm whether it is below the fixed 3.1.4 threshold. The CNA has provided a single mitigation: upgrade to the latest version or later.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the lack of an EPSS value or KEV listing does not diminish the risk of exploitation in a widely deployed plugin. An attacker only needs the ability to submit content as a contributor or obtain a contributor account. If attackers can access the site with a contributor role, they can exploit the vulnerability to run scripts that affect all site users. Prompt patching is therefore recommended to eliminate the exposure.

Generated by OpenCVE AI on September 17, 2026 at 22:12 UTC.

Remediation

Vendor Solution

Update the WordPress PublishPress Series Plugin to the latest available version (at least 3.1.4).


OpenCVE Recommended Actions

  • Update PublishPress Series Plugin to version 3.1.4 or newer
  • If an immediate update is not possible, restrict contributor role capabilities to limit content creation or disable the feature that processes untrusted input
  • Enable a strict Content Security Policy on the site to mitigate potential impact of any residual XSS payloads

Generated by OpenCVE AI on September 17, 2026 at 22:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Publishpress
Publishpress publishpress Series
Wordpress
Wordpress wordpress
Vendors & Products Publishpress
Publishpress publishpress Series
Wordpress
Wordpress wordpress

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.
Title WordPress PublishPress Series plugin <= 3.1.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Publishpress Publishpress Series
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-19T14:21:54.044Z

Reserved: 2026-07-27T14:00:21.730Z

Link: CVE-2026-66617

cve-icon Vulnrichment

Updated: 2026-09-19T14:16:36.422Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:17.623

Modified: 2026-09-19T15:17:00.513

Link: CVE-2026-66617

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')