Description
The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation delays but does not prevent exploitation — once an administrator approves the visually innocuous comment, the stored payload executes in the browser of every subsequent visitor to the affected post.
Published: 2026-10-02
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Apply patch
AI Analysis

Impact

The vulnerability arises from incomplete input sanitization and output escaping in the DoFollow Case by Case plugin. A malicious actor can insert arbitrary JavaScript into a comment, which is stored and rendered on the target post. When an administrator later approves the comment, the payload executes in the browsers of all users viewing the post, enabling theft of credentials, session hijacking, or defacement. This flaw is categorized as CWE‑79.

Affected Systems

Any WordPress site that has the DoFollow Case by Case plugin installed, version 3.6.0 or earlier. The plugin is supplied by the vendor apasionados and is available in the WordPress plugin repository. All versions up to and including 3.6.0 are affected; later releases are not listed as vulnerable.

Risk and Exploitability

With a CVSS score of 7.2 and no EPSS score available, the vulnerability represents a moderate‑to‑high risk. The exploit can be performed without authentication, simply by submitting a crafted comment to an affected post. Comment moderation can delay detection but does not block the payload. Although it is not currently listed in the CISA KEV catalog, the lack of a defensive patch means the risk remains high.

Generated by OpenCVE AI on October 2, 2026 at 08:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the DoFollow Case by Case plugin to the latest release (3.6.1 or later).
  • If the plugin is not essential, remove or disable it to eliminate the vulnerability surface.
  • As a temporary fix, apply server‑side filtering to strip script tags or enforce strict HTML sanitization on comment content, for example by using WordPress’ built‑in wp_filter_nohtml or a similar function.

Generated by OpenCVE AI on October 2, 2026 at 08:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Description The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation delays but does not prevent exploitation — once an administrator approves the visually innocuous comment, the stored payload executes in the browser of every subsequent visitor to the affected post.
Title DoFollow Case by Case <= 3.6.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T07:39:22.487Z

Reserved: 2026-09-22T15:51:14.511Z

Link: CVE-2026-95817

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T08:17:03.933

Modified: 2026-10-02T08:17:03.933

Link: CVE-2026-95817

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T08:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')