Stored XSS Vulnerability in Author Box WP Lens by Netrr
CVE-2026-57420

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 July 2026

What is CVE-2026-57420?

An improper handling of user input during web page generation in the Author Box WP Lens plugin allows for the execution of arbitrary scripts, thus leading to Stored Cross-site Scripting (XSS) vulnerabilities. This affects all versions leading up to and including 2.1.5. Attackers may exploit this vulnerability to inject malicious scripts, potentially compromising user data and security on affected WordPress sites.

Affected Version(s)

Author Box WP Lens 0 <= 2.1.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ParkHyunWoo | Patchstack Bug Bounty Program
.