Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bkninja Gloria Admin Panel gloria-admin-panel allows Reflected XSS.This issue affects Gloria Admin Panel: from n/a through 1.3.
Published: 2026-10-09
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

The Gloria Admin Panel plugin contains an improper neutralization of input during web page generation that permits a reflected cross‑site scripting (XSS) injection. By submitting a crafted value in a request parameter the attacker can have arbitrary scripts executed in the victim's browser, allowing theft of session cookies, defacement of the site, or execution of further malicious payloads. This vulnerability is a classic reflected XSS flaw categorized as CWE‑79.

Affected Systems

The flaw affects the Gloria Admin Panel plugin developed by bkninja for WordPress versions up to and including 1.3. All earlier releases are also vulnerable. The vulnerability is present in any installation that uses these affected plugin versions.

Risk and Exploitability

The CVSS base score of 7.1 indicates a medium‑to‑high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of an exploit probability figure does not reduce the risk. The attack vector is likely a crafted URL or form submission that a user will click or submit, making the exploitation scenario feasible on any site that does not restrict access. An attacker who succeeds could gain the victim’s browser privileges and potentially compromise the site’s integrity or user data.

Generated by OpenCVE AI on October 9, 2026 at 11:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Gloria Admin Panel to a version newer than 1.3, or apply an available vendor patch if one exists.
  • If an upgrade is not yet possible, sanitize all user‑supplied input and encode output (for example, using WordPress esc_html or wp_kses) to prevent script execution.
  • Consider disabling or uninstalling the plugin if it is not required for site functionality.

Generated by OpenCVE AI on October 9, 2026 at 11:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bkninja Gloria Admin Panel gloria-admin-panel allows Reflected XSS.This issue affects Gloria Admin Panel: from n/a through 1.3.
Title WordPress Gloria Admin Panel plugin <= 1.3 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:36.253Z

Reserved: 2026-09-21T00:20:20.797Z

Link: CVE-2026-94158

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T10:16:39.653

Modified: 2026-10-09T10:16:39.653

Link: CVE-2026-94158

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T11:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')