Description
The KeyWord Collector WordPress plugin through 1.4 does not have any authorisation or nonce check when saving its settings, and does not escape them before output, allowing unauthenticated attackers to store malicious JavaScript that executes when an administrator opens the KeyWord Collector WordPress plugin through 1.4's settings page or when a visitor loads a page displaying its output.
Published: 2026-10-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting that executes with admin or visitor privileges
Action: Immediate Patch
AI Analysis

Impact

An unauthenticated attacker can store malicious JavaScript in the settings of KeyWord Collector by submitting data through the settings page. This stored payload is then served to administrators when they open the settings interface and to any visitor who loads a page that displays the plugin’s output. The flaw arises from a lack of authorisation checks and the absence of proper escaping, which allows arbitrary code execution in the context of the rendered page. When executed, the script can read cookies, hijack sessions, modify page content, or carry out other malicious activities.

Affected Systems

All versions of the WordPress plugin KeyWord Collector up to and including 1.4 are affected. The vendor list identifies the product simply as "KeyWord Collector" with no further version detail, indicating the vulnerability spans the entire release set through 1.4. WordPress sites that have this plugin installed, regardless of other configurations, are at risk.

Risk and Exploitability

The vulnerability is a high‑severity stored XSS that does not require prior authentication, meaning an attacker can deliver the malicious payload without logging in. The EPSS score is unavailable, so the likelihood of exploitation is uncertain; however, the absence of a CISA KEV designation suggests it has not yet been confirmed in the wild. Because the flaw allows arbitrary script execution on administrator or visitor pages, the potential impact is escalation of privilege and defacement, making the risk level significant.

Generated by OpenCVE AI on October 11, 2026 at 07:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • If a newer, patched version of KeyWord Collector exists, upgrade the plugin immediately or replace it with a more secure alternative.
  • Deactivating or deleting the KeyWord Collector plugin removes the vulnerable code path and is the simplest mitigation when no patch is available.
  • If continued use of the plugin is required, restrict access to its settings page to administrators only and add an authentication check or nonce mechanism in the settings form to prevent unauthenticated writes or configuration changes.
  • Implement a Content‑Security‑Policy that blocks inline scripts or limits script sources to trusted domains, thereby reducing the impact of any residual stored XSS payloads.

Generated by OpenCVE AI on October 11, 2026 at 07:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-79

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The KeyWord Collector WordPress plugin through 1.4 does not have any authorisation or nonce check when saving its settings, and does not escape them before output, allowing unauthenticated attackers to store malicious JavaScript that executes when an administrator opens the KeyWord Collector WordPress plugin through 1.4's settings page or when a visitor loads a page displaying its output.
Title KeyWord Collector <= 1.4 - Unauthenticated Stored XSS and Settings Update via WPKeyWordSettings
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:42.608Z

Reserved: 2026-09-10T12:18:42.202Z

Link: CVE-2026-88905

cve-icon Vulnrichment

Updated: 2026-10-11T11:18:03.656Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:27.493

Modified: 2026-10-11T12:17:26.147

Link: CVE-2026-88905

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T07:45:18Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')