Description
The Topcontent WordPress plugin through 1.2.1 does not properly authorise one of its request handlers and disables HTML sanitisation before storing the submitted content, allowing unauthenticated attackers to publish arbitrary posts containing malicious JavaScript on any site where its API key has never been configured.
Published: 2026-10-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

A failure to enforce authorization on one of Topcontent’s request handlers allows an attacker without credentials to submit content that the plugin stores without sanitising HTML. The stored data is then rendered as part of a post, enabling the injection of malicious JavaScript into any page that displays the post. This stored XSS flaw can compromise user accounts, deface sites, and serve as a vector for further attacks on visitors. The weakness aligns with common scripting and authorization flaws.

Affected Systems

Any WordPress site that has installed the Topcontent plugin with a version of 1.2.1 or earlier and has not configured an API key is vulnerable. The plugin may appear on sites hosted by a variety of users, from personal blogs to corporate websites, because the flaw is in the public‑facing API endpoint of the plugin.

Risk and Exploitability

The vulnerability can be exploited unauthenticated, meaning any internet‑connected attacker can craft a payload and submit it to the vulnerable endpoint. With a CVSS score of 8.8 and an EPSS score of < 1%, the flaw still poses a high severity risk despite the low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog, but the potential impact of widespread XSS warrants immediate attention.

Generated by OpenCVE AI on October 11, 2026 at 14:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Topcontent plugin to a version newer than 1.2.1
  • Disable the content webhook API to prevent unauthenticated requests until the plugin is updated or configured
  • Configure an API key for the Topcontent plugin, which automatically enables authentication for webhook requests

Generated by OpenCVE AI on October 11, 2026 at 14:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-79

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Topcontent WordPress plugin through 1.2.1 does not properly authorise one of its request handlers and disables HTML sanitisation before storing the submitted content, allowing unauthenticated attackers to publish arbitrary posts containing malicious JavaScript on any site where its API key has never been configured.
Title Topcontent <= 1.2.1 - Unauthenticated Stored XSS via Content Webhook
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:42.722Z

Reserved: 2026-09-10T12:14:29.360Z

Link: CVE-2026-88903

cve-icon Vulnrichment

Updated: 2026-10-11T11:18:18.267Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:27.377

Modified: 2026-10-11T12:17:25.997

Link: CVE-2026-88903

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T08:15:17Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')