Cross-Site Scripting Vulnerability in Hostinger Reach WordPress Plugin
CVE-2026-87777
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 30 September 2026
Badges
What is CVE-2026-87777?
The Hostinger Reach WordPress plugin prior to version 1.8.3 is susceptible to a cross-site scripting vulnerability. This issue arises because the plugin fails to adequately sanitize and escape widget settings before displaying them in the editor preview. As a result, users with contributor-level access and above can inject arbitrary web scripts, leading to potential exploitation when higher-privileged users open the compromised content in the editor. This vulnerability emphasizes the importance of securing widget inputs to protect user sessions and maintain the integrity of web applications.
Affected Version(s)
Hostinger Reach 1.0.6 < 1.8.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.