Stored Cross-Site Scripting Vulnerability in PublishPress Future Plugin for WordPress
CVE-2026-5247
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 May 2026
What is CVE-2026-5247?
The PublishPress Future plugin for WordPress contains a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization on the 'wrapper' attribute of the [futureaction] shortcode. All versions up to and including 4.10.0 are impacted. The plugin's use of esc_html() only encodes HTML entities, which is insufficient to prevent malicious attribute injection when the value is incorporated as an HTML tag name in a sprintf() function. This allows authenticated users with administrator-level access to inject arbitrary scripts into pages. Additionally, because administrators can potentially grant this functionality to lower-privileged users, it raises the risk of exploit by contributors.
Affected Version(s)
Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories 0 <= 4.10.0