Stored Cross-Site Scripting in ThemeRuby Multi Authors Plugin for WordPress
CVE-2026-1097
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 January 2026
What is CVE-2026-1097?
The ThemeRuby Multi Authors plugin for WordPress is exposed to a Stored Cross-Site Scripting vulnerability that arises from inadequate input sanitization and output escaping via the 'before' and 'after' shortcode attributes. Authenticated attackers with Contributor-level access and above can exploit this flaw to inject arbitrary web scripts into pages. These scripts will execute whenever a user accesses the compromised pages, posing significant security risks.
Affected Version(s)
ThemeRuby Multi Authors β Assign Multiple Writers to Posts 0 <= 1.0.0