Executive brief
Patterns Kit is a WordPress plugin that provides pre-built page design patterns, including video popup elements. The plugin fails to properly escape link attributes before inserting them into the page, allowing a contributor-level user to inject malicious scripts that execute when administrators or editors preview their content. An attacker with a basic contributor account can embed XSS payloads that compromise reviewer accounts or perform actions on their behalf.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in the Patterns Kit WordPress plugin through version 1.0.3, specifically affecting the YouTube popup/play-button pattern component. The vulnerability arises because the plugin's client-side JavaScript re-parses link attributes into a new HTML context (an iframe src) without proper escaping, allowing attackers to break out of the attribute using single quotes and inject event handlers like onload. An unauthenticated attacker requires a Contributor role (the lowest role that can author content the plugin renders); the malicious payload is stored in the post and executes when an Editor or Administrator previews or views the content and clicks the affected element. The attack bypasses WordPress's default HTML filtering (wp_kses) because the payload is initially stored as entity-encoded and appears benign, but is decoded and re-contextualized by the plugin's front-end code. There is no known patch as of the advisory date.
Affected products
- Patterns Kit Patterns Kit through 1.0.3
Timeline
- 2026-08-10: disclosed
- 2026-08-12: advisory