Stored Cross-Site Scripting in CI HUB Connector Plugin for WordPress
CVE-2026-4353
6.4MEDIUM
What is CVE-2026-4353?
The CI HUB Connector plugin for WordPress is susceptible to Stored Cross-Site Scripting through the 'id' attribute of the cihub_metadata shortcode. This vulnerability arises due to inadequate input sanitization and output escaping in all versions up to and including 1.2.106. Authenticated attackers, who have at least Contributor-level access, can exploit this vulnerability to inject arbitrary web scripts into pages, resulting in code execution whenever a user accesses the compromised page.
Affected Version(s)
CI HUB Connector 0 <= 1.2.106