Junglewise Threat Intelligence

CVE-2026-17010: Saitama Addon Pack stored XSS in post metadata

CVE-2026-17010 · Severity: medium · CVSS 5.4 · Published 2026-08-10

Executive brief

The Saitama Addon Pack is a WordPress plugin that extends site functionality with SEO and content management features. When administrators enable post meta keyword and description fields, contributors can inject malicious JavaScript code that executes in the browsers of editors and administrators when they review the content, potentially allowing attackers to steal sessions, modify content, or perform unauthorized actions within the WordPress admin panel.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in post metadata handling. The plugin fails to sanitize and escape values from the "Meta Keywords" and "Meta Description" metaboxes before outputting them in the post editor (wp-admin). Contributors and above can submit posts with injected script tags in these fields. When a higher-privileged user (editor or administrator) opens the post for review, the unescaped JavaScript executes within their authenticated wp-admin session. The vulnerability requires the administrator to have enabled both the "Print Meta keyword" and "Print Meta description" options (disabled by default). The payload does not execute on the front-end because front-end output is properly escaped. The issue is fixed in version 1.0.9.

Affected products

  • Saitama Addon Pack through 1.0.8

Timeline

  • 2026-08-05: disclosed: Publicly published on WPScan
  • 2026-08-10: advisory: NVD published CVE-2026-17010
  • 2026-08-10: patched: Fixed in version 1.0.9

References