Stored Cross-Site Scripting Vulnerability in VK All in One Expansion Unit Plugin for WordPress
CVE-2026-17586

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 September 2026

What is CVE-2026-17586?

The VK All in One Expansion Unit plugin for WordPress has a Stored Cross-Site Scripting vulnerability through the 'vkExUnit_cta_img_position' Post Meta. This issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with contributor access or higher to inject malicious web scripts. These scripts execute when users access the affected pages. Specifically, the sanitize_text_field function fails to remove double-quote characters and event-handler attributes, while the output filter Vk_Call_To_Action::safe_kses_post() inadequately rewrites disallowed iframe elements, preserving the malicious payload in the final HTML. Users should take precautionary measures to secure their installations.

Affected Version(s)

VK All in One Expansion Unit 0 <= 9.118.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kyokito
Athiwat Tiprasaharn (Jitlada)
Itthidej Aramsri (Boeing777)
.