Improper Authorization in Topcontent Plugin for WordPress
CVE-2026-88903

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 October 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-88903?

The Topcontent WordPress plugin prior to version 1.2.1 has a critical security flaw that allows unauthenticated attackers to exploit a lack of authorization in one of its request handlers. By not implementing proper HTML sanitization, the plugin enables these attackers to submit arbitrary posts containing malicious JavaScript, thereby compromising the security of any WordPress site where its API key is not configured. This vulnerability emphasizes the importance of securing plugin request handlers to prevent unauthorized content publication.

Affected Version(s)

Topcontent 0 <= 1.2.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Naoki Kawahigashi
WPScan
.