Stored Cross-Site Scripting Vulnerability in Institute Management Plugin for WordPress
CVE-2026-2714

4.4MEDIUM

What is CVE-2026-2714?

The Institute Management plugin for WordPress contains a Stored Cross-Site Scripting vulnerability that allows authenticated users with administrative privileges to inject malicious web scripts through the 'Enquiry Form Title' setting. This issue arises from inadequate input sanitization and output escaping, affecting installations where unfiltered_html is disabled, particularly in multi-site configurations. When a user visits a page with the injected script, the attacker's code will execute, potentially compromising site integrity and user data.

Affected Version(s)

Institute Management – Learning Management System 0 <= 5.5

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ritesh Sahu
.