Cross-Site Scripting Vulnerability in Hostinger Reach WordPress Plugin
CVE-2026-87777

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
30 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-87777?

The Hostinger Reach WordPress plugin prior to version 1.8.3 is susceptible to a cross-site scripting vulnerability. This issue arises because the plugin fails to adequately sanitize and escape widget settings before displaying them in the editor preview. As a result, users with contributor-level access and above can inject arbitrary web scripts, leading to potential exploitation when higher-privileged users open the compromised content in the editor. This vulnerability emphasizes the importance of securing widget inputs to protect user sessions and maintain the integrity of web applications.

Affected Version(s)

Hostinger Reach 1.0.6 < 1.8.3

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
WPScan
.