Impact
The Extendify WordPress plugin is vulnerable to a stored cross‑site scripting flaw caused by insufficient sanitization and output escaping of the 'styles.blocks' block type key. An unauthenticated attacker can send a crafted POST, PUT, or PATCH request to the /wp/v2/global-styles REST route, exploiting the fact that the plugin’s registerIncoming() handler runs before WordPress checks permissions. This allows an attacker to persist arbitrary JavaScript in the plugin’s data. The script executes in the browser of any user who visits a page that loads the affected global style, enabling attackers to steal cookies, hijack sessions, deface pages, or execute additional malicious actions. The weakness is identified as CWE‑79.
Affected Systems
The issue affects the Extendify plugin for WordPress in all releases up to and including version 3.1.6. Any WordPress instance that has the vulnerable plugin installed is at risk, regardless of user authentication status, because the flaw is triggered by unauthenticated API calls.
Risk and Exploitability
With a CVSS score of 7.2, this vulnerability is classified as high severity. The EPSS score is not available, and it does not appear on the CISA KEV list, but the lack of an authentication barrier and the direct REST‑API entry point mean exploitation is straightforward for an attacker with network access to the site. An attacker only needs to send a simple HTTP request containing malicious script in the 'styles.blocks' field; no additional credentials or complex conditions are required. The stored nature of the XSS means the effect persists until the plugin is patched or the unsafe data is removed.
OpenCVE Enrichment