Description
Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.
Published: 2026-08-31
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated cross-site scripting flaw in the Tailored Tools WordPress plugin affects all versions up to 3.0.2, allowing the insertion of arbitrary JavaScript into pages served by the plugin. The lack of an authentication requirement means any user who can access the plugin's public interfaces can exploit the flaw. Based on the description, it is inferred that the vulnerability can be triggered by supplying malicious payloads through URLs or form submissions that the plugin processes without proper sanitization.

Affected Systems

Affected systems are WordPress installations that have the Tailored Media Tailored Tools plugin version 3.0.2 or earlier installed. No particular server configuration, theme, or WordPress core version is required for exploitation, so any site using the vulnerable plugin version is at risk.

Risk and Exploitability

CVSS score of 7.1 classifies this issue as high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet. The exploit probability remains uncertain, but the absence of any authentication barrier implies that an attacker can initiate the attack from outside the site by crafting a malicious request targeting the plugin’s endpoints. Though no confirmed attack patterns are reported, the combination of high severity and broad impact makes the flaw a tangible risk for WordPress sites deploying the plugin.

Generated by OpenCVE AI on August 31, 2026 at 21:54 UTC.

Remediation

Vendor Solution

Update the WordPress Tailored Tools Plugin to the latest available version (at least 3.0.3).


OpenCVE Recommended Actions

  • Update the Tailored Tools plugin to version 3.0.3 or later, which removes the XSS flaw.
  • If an immediate update is not possible, temporarily disable the plugin to eliminate the attack surface.
  • As a short-term measure, configure a web application firewall or similar rule set to block script injection attempts aimed at the Tailored Tools plugin’s endpoints.

Generated by OpenCVE AI on August 31, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.
Title WordPress Tailored Tools plugin <= 3.0.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-31T20:30:50.339Z

Reserved: 2026-08-27T12:22:09.413Z

Link: CVE-2026-81765

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T21:17:51.537

Modified: 2026-08-31T21:17:51.537

Link: CVE-2026-81765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T22:00:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')