Description
The SmugMug Embed WordPress plugin through 3.13 does not have authorisation or CSRF checks on an AJAX action that stores gallery data, and does not sanitise or escape that data before outputting it, allowing unauthenticated users to store arbitrary web scripts that execute when an administrator views the SmugMug Embed WordPress plugin through 3.13's settings screen.
Published: 2026-10-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting via unauthenticated AJAX action
Action: Immediate Patch
AI Analysis

Impact

The SmugMug Embed WordPress plugin up to version 3.13 lacks authentication and CSRF checks on an AJAX action that stores gallery data and fails to sanitise or escape that data before outputting it. This allows any unauthenticated user to inject arbitrary JavaScript that is stored and executed when an administrator later views the plugin’s settings screen. The stored script runs with the privileges of the logged‑in administrator, enabling defacement, credential theft, or further exploitation of the site. The impact therefore includes a compromise of administrator confidentiality, integrity, and availability of the WordPress dashboard.

Affected Systems

Products affected are the SmugMug Embed WordPress plugin from the vendor listed as Unknown:SmugMug Embed, versions through and including 3.13. No other variant or version is specified in the available data.

Risk and Exploitability

The vulnerability is a classic stored XSS flaw, which is high‑impact when the administrator’s browser processes the stored script. Attackers can exploit the flaw by sending a crafted AJAX request without authentication; the lack of CSRF protections means the request can be triggered from any client, including untrusted networks. The CVSS score is 8.8, the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating that while it can be exploited, it is not known to have been widely used in the wild. Nevertheless, the potential for severe impact warrants immediate attention.

Generated by OpenCVE AI on October 11, 2026 at 14:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the SmugMug Embed plugin to version 3.14 or later, where the vulnerability is resolved.
  • If an immediate update is not feasible, block endpoint (e.g., via .htaccess or server‑side access controls) so that only authenticated administrator users can invoke it.
  • As a temporary precaution, enable a stringent Content‑Security‑Policy on the WordPress admin interface to block inline scripting and mitigate the risk of stored script execution.

Generated by OpenCVE AI on October 11, 2026 at 14:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The SmugMug Embed WordPress plugin through 3.13 does not have authorisation or CSRF checks on an AJAX action that stores gallery data, and does not sanitise or escape that data before outputting it, allowing unauthenticated users to store arbitrary web scripts that execute when an administrator views the SmugMug Embed WordPress plugin through 3.13's settings screen.
Title SmugMug Embed <= 3.13 - Unauthenticated Stored XSS via saveSelectedAlbums
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:42.963Z

Reserved: 2026-09-10T09:31:32.078Z

Link: CVE-2026-88826

cve-icon Vulnrichment

Updated: 2026-10-11T11:18:47.143Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:27.153

Modified: 2026-10-11T12:17:25.700

Link: CVE-2026-88826

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:15:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')