Stored Cross-Site Scripting in rexCrawler Plugin for WordPress
CVE-2026-2280

4.8MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 May 2026

What is CVE-2026-2280?

The rexCrawler plugin for WordPress is affected by a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping within its admin settings. Authenticated attackers with administrator-level permissions can exploit this issue to inject arbitrary scripts that execute when users access affected pages. This vulnerability specifically impacts multi-site installations and those where unfiltered HTML is disabled, making it crucial for site administrators to implement patches and enhance their security measures.

Affected Version(s)

rexCrawler 0 <= 1.0.15

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

san6051
.