Description
The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'file_list' Field Type in all versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when an integrating plugin or theme registers a file_list field on a publicly accessible front-end form or a user meta box, as CMB2 is a developer library and does not expose these fields by default.
Published: 2026-10-02
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting that injects and executes arbitrary scripts on vulnerable pages
Action: Immediate Patch
AI Analysis

Impact

The CMB2 WordPress plugin contains a stored XSS flaw in the 'file_list' field type due to inadequate sanitization and output escaping. An attacker can embed malicious scripts that will run in the browser of any visitor who loads a page containing the injected value. This can lead to session hijacking, data theft, or defacement of the site. The vulnerability is classified as CWE‑79 and results in a CVSS score of 7.2.

Affected Systems

Any WordPress site that uses CMB2 version 2.13.0 or older and that registers a public file_list field through an integrating plugin or theme. The issue does not exist in later CMB2 releases; thus sites running ≥2.13.1 are not affected. Vulnerability is limited to publicly exposed front‑end forms or user meta boxes that expose file_list fields.

Risk and Exploitability

The CVSS score of 7.2 indicates moderate to high severity, but the exploitability depends on whether a public file_list field is present. Because the EPSS score is not available and the vulnerability is not listed in CISA KEV, the overall risk is considered medium; however sites that expose the vulnerable field to unauthenticated users face a high likelihood of successful exploitation if an attacker obtains a payload. The attack vector is client‑side, making the discovery and exploitation straightforward for anyone who can influence the form content.

Generated by OpenCVE AI on October 2, 2026 at 08:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the CMB2 plugin to the latest available version, which fixes the file_list field sanitization issue.
  • If a recent version cannot be used, remove or disable any publicly accessible file_list fields or restrict them to authenticated users only.
  • Audit all plugins and themes that register CMB2 file_list fields to ensure they are not exposed on public forms; apply proper input validation and output escaping as a fallback if the field cannot be removed.

Generated by OpenCVE AI on October 2, 2026 at 08:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Description The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'file_list' Field Type in all versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when an integrating plugin or theme registers a file_list field on a publicly accessible front-end form or a user meta box, as CMB2 is a developer library and does not expose these fields by default.
Title CMB2 <= 2.13.0 - Unauthenticated Stored Cross-Site Scripting via 'file_list' Field Type
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T07:39:22.150Z

Reserved: 2026-09-24T12:22:15.727Z

Link: CVE-2026-97336

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T08:17:04.983

Modified: 2026-10-02T08:17:04.983

Link: CVE-2026-97336

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T08:45:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')