Stored Cross-Site Scripting in ITERAS Plugin for WordPress
CVE-2026-4078
6.4MEDIUM
What is CVE-2026-4078?
The ITERAS plugin for WordPress contains a vulnerability that allows for Stored Cross-Site Scripting through several shortcodes, affecting all versions up to 1.8.2. The issue arises from inadequate input sanitization and output escaping in the combine_attributes() function. By inserting a double-quote character in a shortcode attribute, an attacker can manipulate the JavaScript string context, enabling the injection of arbitrary web scripts into pages. This can be exploited by authenticated users with Contributor-level access and above, leading to potential attacks whenever a user accesses an affected page.
Affected Version(s)
ITERAS 0 <= 1.8.2