Stored Cross-Site Scripting in CMB2 Plugin for WordPress
CVE-2026-102772

7.2HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-102772?

The CMB2 plugin for WordPress is susceptible to stored cross-site scripting, caused by inadequate input sanitization and output escaping in the '<textarea_code field id>' parameter. This vulnerability affects all versions up to and including 2.13.1. Unauthenticated attackers can exploit this weakness, allowing them to inject malicious web scripts into pages that execute when a user visits an affected page. The vulnerability arises from the design of the front-end save path, which only requires a nonce that is accessible to all visitors, including unauthenticated users. This ease of access renders the attack highly feasible on websites with publicly accessible CMB2 forms.

Affected Version(s)

CMB2 0 <= 2.13.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kuba
.