SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84899

MEDIUM · CVSS 6.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The VikWidgetsLoader WordPress plugin prior to version 1.12.0 is vulnerable due to improper sanitization of a block attribute, enabling users with Contributor roles to inject arbitrary JavaScript into posts. This flaw allows the injected scripts to execute in the browsers of all users, including administrators, potentially leading to session hijacking or other malicious actions. WordPress site administrators and security teams should prioritize this vulnerability to mitigate risks associated with unauthorized script execution.

CVE
CVE-2026-84899
Severity
MEDIUM
CVSS
6.8
EPSS
0.24%
WordPress Java

Original NVD Description

The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who reviews the pending submission.