Executive brief
ManageWP Worker is a WordPress plugin used to connect websites to the ManageWP management dashboard. A security flaw allows unauthenticated attackers to inject malicious scripts into the website, which could lead to unauthorized actions being performed in a site administrator's browser, such as redirecting visitors to malicious sites or stealing session information. This occurs when a logged-in administrator interacts with a specially crafted link or page created by the attacker.
Technical details
The ManageWP Worker plugin for WordPress is vulnerable to Unauthenticated Reflected Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation (CWE-79). The vulnerability exists in versions up to and including 4.9.31. An unauthenticated attacker can exploit this by tricking a privileged user (such as an administrator) into clicking a malicious link or visiting a crafted page. Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions. The issue is resolved in version 4.9.32.
Affected products
- ManageWP ManageWP Worker <= 4.9.31
Timeline
- 2026-01-10: other: Reported by Steven Julian
- 2026-04-13: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date