Executive brief
Auros Core, a WordPress plugin used for site functionality, contains a security flaw that allows unauthorized individuals to inject their own content into the website. An attacker could use this to display misleading information or create fake login pages to steal user credentials. This can damage a company's reputation and lead to phishing attacks against its customers.
Technical details
Auros Core versions up to and including 5.3.1 are vulnerable to unauthenticated content injection. The vulnerability stems from improper neutralization of script-related HTML tags (CWE-80), allowing an attacker to inject arbitrary content into web pages. This is a network-based attack that requires no prior authentication or user interaction. Successful exploitation allows for the modification of site content or the creation of phishing pages. As of the advisory date, no official patch has been released.
Affected products
- Opal_WP Auros Core <= 5.3.1
Timeline
- 2025-10-19: disclosed: Reported by Bonds
- 2026-06-26: advisory: Published by Patchstack and NVD