Junglewise Threat Intelligence

CVE-2026-28116: Emilia Projects Progress Planner Stored XSS

CVE-2026-28116 · Severity: medium · CVSS 5.9 · Published 2026-06-02

Executive brief

Progress Planner, a WordPress plugin used for project management and tracking, contains a security vulnerability that allows for stored cross-site scripting. An attacker with high-level privileges, such as an Editor, can inject malicious scripts into the website. These scripts are then executed in the browsers of other users, potentially leading to unauthorized redirects, malicious advertisements, or the theft of session information.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Emilia Projects Progress Planner plugin for WordPress due to improper neutralization of user input during web page generation. The flaw allows an authenticated attacker with high-level privileges (such as an Editor) to inject arbitrary web scripts into the application. Successful exploitation requires a victim to interact with the affected page or link. The injected scripts execute within the context of the victim's browser session, which could lead to data exfiltration or unauthorized actions. The issue is addressed in version 1.9.1.

Affected products

  • Emilia Projects Progress Planner <= 1.9.0

Timeline

  • 2025-08-21: other: Reported by researcher hongdo
  • 2026-06-02: advisory: Published by Patchstack and NVD
  • 2026-06-02: patched: Fixed in version 1.9.1

References