Stored Cross-Site Scripting in Presto Player Plugin for WordPress
CVE-2026-96682

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 October 2026

What is CVE-2026-96682?

The Presto Player plugin for WordPress presents a Stored Cross-Site Scripting vulnerability, allowing unauthenticated attackers to inject malicious scripts through comment content in pages. This issue arises from inadequate input sanitization and output escaping in the tag. Initially, an attacker must have their comment approved, but due to WordPress's default settings, all subsequent comments from the same author are automatically approved, enabling potential exploitation of web pages without further intervention from site administrators.

Affected Version(s)

Presto Player 0 <= 4.5.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

20kilograma
.