Stored Cross-Site Scripting Vulnerability in VK All in One Expansion Unit Plugin for WordPress
CVE-2026-17586
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 September 2026
What is CVE-2026-17586?
The VK All in One Expansion Unit plugin for WordPress has a Stored Cross-Site Scripting vulnerability through the 'vkExUnit_cta_img_position' Post Meta. This issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with contributor access or higher to inject malicious web scripts. These scripts execute when users access the affected pages. Specifically, the sanitize_text_field function fails to remove double-quote characters and event-handler attributes, while the output filter Vk_Call_To_Action::safe_kses_post() inadequately rewrites disallowed iframe elements, preserving the malicious payload in the final HTML. Users should take precautionary measures to secure their installations.
Affected Version(s)
VK All in One Expansion Unit 0 <= 9.118.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved