AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-17010

MEDIUM · CVSS 5.4 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Saitama Addon Pack plugin for WordPress versions up to 1.0.8 is vulnerable due to insufficient sanitization and escaping of post metadata, enabling users with contributor-level access or higher to inject stored Cross-Site Scripting (XSS) payloads. This vulnerability can lead to the execution of malicious scripts in the browsers of higher-privileged users reviewing the affected content. WordPress site administrators and developers using this plugin should prioritize immediate updates to mitigate potential security risks.

CVE
CVE-2026-17010
Severity
MEDIUM
CVSS
5.4
EPSS
0.16%
WordPress

Original NVD Description

The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing users with contributor-level access and above to inject stored Cross-Site Scripting payloads that execute in the browser of a higher-privileged user who reviews the content.