Stored Cross-Site Scripting Vulnerability in ZeM STL Plugin for WordPress
CVE-2026-4081
6.4MEDIUM
What is CVE-2026-4081?
The ZeM STL plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability through the '[zemstl]' shortcode. This occurs because user-supplied attributes such as 'url', 'color', and 'bgcolor' are not adequately sanitized or escaped. As a result, an authenticated attacker with Contributor-level access or higher can inject malicious web scripts into the HTML context of the page. The absence of proper escaping functions allows these scripts to execute whenever a user visits an affected page, potentially leading to unauthorized actions or data exposure.
Affected Version(s)
ZeM STL 0 <= 1.0