Executive brief
LPagery, a WordPress plugin used for bulk page generation, contains a security flaw that allows users with low-level access (like Contributors) to inject malicious scripts into the website's administrative dashboard. These scripts are triggered when a site administrator views specific pages, potentially allowing the attacker to perform unauthorized actions or steal sensitive information. This could lead to a full compromise of the website if an administrator's session is hijacked.
Technical details
The LPagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the lpagery_add_filter_text_template_post() function. This function, hooked to admin_footer, echoes the raw post_title of a post referenced by the 'lpagery_template' query parameter directly into a JavaScript single-quoted string literal without using esc_js() or esc_html(). Authenticated attackers with Contributor-level permissions can exploit this by creating a post with a malicious title. The script executes when a higher-privileged user, such as an administrator, accesses an admin page with the specific query parameter pointing to the attacker's post ID. A patch is available in versions following 2.5.7.
Affected products
- niklaslindemann Bulk Page Generator – LPagery up to, and including, 2.5.7
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory
References
- https://plugins.trac.wordpress.org/browser/lpagery/tags/2.5.7/lpagery.php
- https://plugins.trac.wordpress.org/browser/lpagery/tags/2.5.7/lpagery.php
- https://plugins.trac.wordpress.org/browser/lpagery/tags/2.5.7/lpagery.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3611156%40lpagery&new=3611156%40lpagery
- https://www.wordfence.com/threat-intel/vulnerabilities/id/6720e68e-16fc-48c2-ad56-1f44a3e78bb2?source=cve