Executive brief
PublishPress Post Expirator is a WordPress plugin used to automate the expiration and deletion of posts. A security vulnerability in this plugin could allow an attacker with basic contributor access to inject malicious scripts into the website. If a site administrator or visitor views the affected content, the script could execute, potentially leading to unauthorized redirects, the display of fraudulent advertisements, or the theft of session information.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the PublishPress Post Expirator plugin (also known as post-expirator) due to improper neutralization of input during web page generation. The flaw allows an authenticated attacker with 'Contributor' level permissions or higher to inject malicious JavaScript into the Document Object Model (DOM). Successful exploitation requires a victim (such as an administrator) to interact with a specific page or link. This can lead to the execution of arbitrary code in the context of the victim's browser session, potentially allowing for session hijacking or site defacement. The issue is resolved in version 4.10.0.
Affected products
- PublishPress Post Expirator <= 4.9.4
Timeline
- 2026-02-20: other: Vulnerability reported by researcher timomangcut
- 2026-03-22: patched: Patch released in version 4.10.0
- 2026-04-08: disclosed: CVE published to NVD