Description
The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' Block Type Key in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because registerIncoming() is hooked on rest_request_before_callbacks and runs before WordPress evaluates the route's permission_callback, meaning any unauthenticated POST, PUT, or PATCH request to a /wp/v2/global-styles route can trigger the vulnerable code path.
Published: 2026-10-01
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The Extendify WordPress plugin is vulnerable to a stored cross‑site scripting flaw caused by insufficient sanitization and output escaping of the 'styles.blocks' block type key. An unauthenticated attacker can send a crafted POST, PUT, or PATCH request to the /wp/v2/global-styles REST route, exploiting the fact that the plugin’s registerIncoming() handler runs before WordPress checks permissions. This allows an attacker to persist arbitrary JavaScript in the plugin’s data. The script executes in the browser of any user who visits a page that loads the affected global style, enabling attackers to steal cookies, hijack sessions, deface pages, or execute additional malicious actions. The weakness is identified as CWE‑79.

Affected Systems

The issue affects the Extendify plugin for WordPress in all releases up to and including version 3.1.6. Any WordPress instance that has the vulnerable plugin installed is at risk, regardless of user authentication status, because the flaw is triggered by unauthenticated API calls.

Risk and Exploitability

With a CVSS score of 7.2, this vulnerability is classified as high severity. The EPSS score is not available, and it does not appear on the CISA KEV list, but the lack of an authentication barrier and the direct REST‑API entry point mean exploitation is straightforward for an attacker with network access to the site. An attacker only needs to send a simple HTTP request containing malicious script in the 'styles.blocks' field; no additional credentials or complex conditions are required. The stored nature of the XSS means the effect persists until the plugin is patched or the unsafe data is removed.

Generated by OpenCVE AI on October 1, 2026 at 06:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Extendify plugin to the latest available version (3.2.0 or newer); the update removes the vulnerable code path.
  • If an update cannot be applied immediately, block or restrict access to the /wp/v2/global-styles REST endpoint using a firewall rule or a security plugin to prevent unauthenticated POST, PUT, or PATCH requests.
  • Apply a custom filter or patch that sanitizes the 'styles.blocks' input and ensures proper escaping when outputting global style data, thereby mitigating the XSS weakness indicated by CWE‑79.

Generated by OpenCVE AI on October 1, 2026 at 06:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' Block Type Key in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because registerIncoming() is hooked on rest_request_before_callbacks and runs before WordPress evaluates the route's permission_callback, meaning any unauthenticated POST, PUT, or PATCH request to a /wp/v2/global-styles route can trigger the vulnerable code path.
Title Extendify <= 3.1.6 - Unauthenticated Stored Cross-Site Scripting via 'styles.blocks' Block Type Key
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-01T05:30:55.047Z

Reserved: 2026-09-04T13:38:58.902Z

Link: CVE-2026-85679

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T06:17:11.577

Modified: 2026-10-01T06:17:11.577

Link: CVE-2026-85679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T06:30:01Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')