AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-13701

MEDIUM · CVSS 4.8 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Advanced Excerpt WordPress plugin prior to version 4.5 is vulnerable due to inadequate sanitization and escaping of a setting, potentially allowing administrators to introduce Stored Cross-Site Scripting (XSS) attacks. This vulnerability can lead to malicious scripts being executed in the context of any visitor to the affected site, posing a significant risk to user data and site integrity. WordPress site administrators, particularly those managing multisite environments, should prioritize updating this plugin to mitigate the risk.

CVE
CVE-2026-13701
Severity
MEDIUM
CVSS
4.8
EPSS
0.17%
WordPress

Original NVD Description

The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it on the front end of the site, which could allow administrators (including those without the unfiltered_html capability, such as on multisite) to perform Stored Cross-Site Scripting attacks that execute in the context of any visitor viewing affected pages.