Stored Cross-Site Scripting Vulnerability in PublishPress Future Plugin for WordPress
CVE-2026-5247

5.5MEDIUM

What is CVE-2026-5247?

The PublishPress Future plugin for WordPress contains a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization on the 'wrapper' attribute of the [futureaction] shortcode. All versions up to and including 4.10.0 are impacted. The plugin's use of esc_html() only encodes HTML entities, which is insufficient to prevent malicious attribute injection when the value is incorporated as an HTML tag name in a sprintf() function. This allows authenticated users with administrator-level access to inject arbitrary scripts into pages. Additionally, because administrators can potentially grant this functionality to lower-privileged users, it raises the risk of exploit by contributors.

Affected Version(s)

Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories 0 <= 4.10.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Djaidja Moundjid
.