Cross-Site Scripting Vulnerability in Text Styler Plugin for WordPress
CVE-2026-88788

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-88788?

The Text Styler WordPress plugin, up to version 1.1.1, is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user-supplied styling values. This vulnerability enables users with contributor-level access or higher to introduce malicious JavaScript into the output. As the plugin fails to verify user permissions for editing target posts, any individual viewing an affected post, including site administrators, may have their browsers compromised. It is crucial for site administrators to update to the latest version to mitigate potential security risks associated with this vulnerability.

Affected Version(s)

Text Styler 0 <= 1.1.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pablo González Pérez
Francisco José Ramírez Vicente
and Iñigo Sánchez Enciso
WPScan
.