Description
Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.
Published: 2026-09-10
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting (XSS)
Action: Patch Now
AI Analysis

Impact

Unauthenticated Cross Site Scripting (XSS) is present in WPCS versions up to 1.3.2. The flaw allows an attacker to inject arbitrary client‑side script into web pages served by WordPress sites that host the affected plugin. The injected code can run in the context of the victim’s browser, enabling cookie theft, session hijacking, defacement, and delivery of additional malware. The vulnerability is a classic input‑validation weakness (CWE-79).

Affected Systems

RealMag777’s WPCS WordPress plugin for sites that have installed any version of the software up through 1.3.2 is affected. Sites using earlier versions or the updated 1.3.3 and later are safe from this specific flaw.

Risk and Exploitability

The Common Vulnerability Scoring System gives this flaw a 7.1 score, indicating a medium‑to‑high severity. The Exploit Prediction Scoring System (EPSS) is not available, so the current exploit probability is not quantified. This entry is not listed in CISA’s Known Exploited Vulnerabilities catalog, but the unauthenticated nature of the flaw means that any visitor to a vulnerable site could potentially trigger the vulnerability. Attackers would typically craft a malicious URL or input that is echoed by the plugin without proper encoding, then lure a target user to the page to execute the injected script. Because the vulnerability is cross‑site, it can affect all users who load the affected page.

Generated by OpenCVE AI on September 10, 2026 at 16:09 UTC.

Remediation

Vendor Solution

Update the WordPress WPCS Plugin to the latest available version (at least 1.3.3).


OpenCVE Recommended Actions

  • Update the WPCS plugin to version 1.3.3 or later.
  • If the plugin is no longer required, disable or uninstall it from the WordPress installation.
  • Apply additional input sanitization or a web‑application firewall rule to block scripts in incoming requests as a temporary protection.

Generated by OpenCVE AI on September 10, 2026 at 16:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Realmag777
Realmag777 wpcs
Wordpress
Wordpress wordpress
Vendors & Products Realmag777
Realmag777 wpcs
Wordpress
Wordpress wordpress

Thu, 10 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.
Title WordPress WPCS plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Realmag777 Wpcs
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-11T20:19:12.902Z

Reserved: 2026-09-02T10:29:50.811Z

Link: CVE-2026-84816

cve-icon Vulnrichment

Updated: 2026-09-11T20:13:23.006Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T15:17:48.817

Modified: 2026-09-11T21:17:28.243

Link: CVE-2026-84816

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T10:15:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')