Cross-Site Scripting Vulnerability in Tag Groups Plugin for WordPress
CVE-2026-9833
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 July 2026
Badges
What is CVE-2026-9833?
The Tag Groups plugin for WordPress versions prior to 2.2.0 is susceptible to a Cross-Site Scripting (XSS) vulnerability due to improper escaping of AJAX parameters. This flaw allows unauthenticated attackers to execute arbitrary JavaScript in the browser of any logged-in user with Editor level access who is lured into clicking a manipulated link. By exploiting this vulnerability, attackers can gain control over user sessions and potentially compromise sensitive data.
Affected Version(s)
Tag Groups is the Advanced Way to Display Your Taxonomy Terms 0 < 2.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved