Stored Cross-Site Scripting Vulnerability in Saitama Addon Pack for WordPress
CVE-2026-17010
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 10 August 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-17010?
The Saitama Addon Pack for WordPress versions up to 1.0.8 is prone to a stored Cross-Site Scripting (XSS) vulnerability. This flaw arises from the plugin's failure to properly sanitize and escape specific post metadata values before rendering them in the browser. As a result, users with contributor-level access and higher can inject malicious scripts that may execute when a privileged user views the content. This could lead to unauthorized actions or data exposure for users with higher permissions.
Affected Version(s)
Saitama Addon Pack 0 <= 1.0.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.