Stored Cross-Site Scripting Vulnerability in Twentig Plugin for WordPress
CVE-2026-2602
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 March 2026
What is CVE-2026-2602?
The Twentig plugin for WordPress, up to version 1.9.7, is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping in the 'featuredImageSizeWidth' parameter. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into pages. Such scripts execute whenever a user visits the affected page, potentially compromising user security and privacy.
Affected Version(s)
Twentig Supercharged Block Editor β Blocks, Patterns, Starter Sites, Portfolio 0 <= 1.9.7