Stored Cross-Site Scripting in CMB2 Plugin for WordPress
CVE-2026-102772
7.2HIGH
What is CVE-2026-102772?
The CMB2 plugin for WordPress is susceptible to stored cross-site scripting, caused by inadequate input sanitization and output escaping in the '<textarea_code field id>' parameter. This vulnerability affects all versions up to and including 2.13.1. Unauthenticated attackers can exploit this weakness, allowing them to inject malicious web scripts into pages that execute when a user visits an affected page. The vulnerability arises from the design of the front-end save path, which only requires a nonce that is accessible to all visitors, including unauthenticated users. This ease of access renders the attack highly feasible on websites with publicly accessible CMB2 forms.
Affected Version(s)
CMB2 0 <= 2.13.1