Stored Cross-Site Scripting Vulnerability in Vigilant WordPress Security Suite
CVE-2026-81754
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 September 2026
What is CVE-2026-81754?
The Vigilant – 100% Free Security Suite for WordPress suffers from a Stored Cross-Site Scripting vulnerability. This issue arises from inadequate input sanitization and output escaping regarding the User-Agent header. Attackers can exploit this security gap to inject arbitrary scripts that will be executed when users access compromised pages. The injection occurs silently during failed login attempts, enabling an attacker to deliver a malicious payload without the need for further engagement once stored.
Affected Version(s)
Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… 0 <= 2.10.2