Junglewise Threat Intelligence

CVE-2026-14234: WOLF WordPress plugin stored XSS via CSRF in AJAX action

CVE-2026-14234 · Severity: info · CVSS 7.1 · Published 2026-07-29

Vendors: Unknown.

Executive brief

A vulnerability in the WOLF WordPress plugin, used for bulk editing posts, allows an attacker to inject malicious scripts into a website's content. By tricking a logged-in administrator into clicking a malicious link, the attacker can silently modify existing posts to include harmful code. This could lead to the theft of user sessions, website defacement, or the redirection of visitors to malicious sites.

Technical details

The WOLF plugin (bulk-editor) fails to implement nonce verification or capability checks on the 'wpbe_redraw_table_row' AJAX action. An unauthenticated attacker can exploit this by crafting a malicious request that targets a logged-in administrator. If the administrator visits a malicious site, a CSRF attack triggers the vulnerable AJAX handler to overwrite the 'post_content' field of a specified post with arbitrary data. On standard WordPress installations where administrators have 'unfiltered_html' privileges, this allows for the injection of raw scripts, resulting in Stored XSS. The issue is fixed in version 1.1.0.

Affected products

  • Unknown WOLF – WordPress Posts Bulk Editor and Manager < 1.1.0

Timeline

  • 2026-07-08: disclosed: Publicly published by WPScan
  • 2026-07-29: advisory: NVD published date
  • 2026-07-29: patched: Fixed in version 1.1.0

References