Junglewise Threat Intelligence

CVE-2026-39483: Hidekazu Ishikawa VK All in One Expansion Unit Stored XSS

CVE-2026-39483 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Executive brief

The VK All in One Expansion Unit plugin for WordPress, which provides various site enhancement features, is vulnerable to a security flaw that allows users with low-level permissions to inject malicious scripts. If an administrator or site visitor views the affected content, these scripts could execute, potentially leading to unauthorized redirects, site defacement, or the theft of sensitive session information. This could damage a site's reputation and compromise user security.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the VK All in One Expansion Unit plugin for WordPress (versions up to and including 9.113.3). The flaw stems from improper neutralization of user-supplied input during web page generation, allowing an attacker with 'Contributor' level privileges or higher to inject malicious scripts into the site's database. These scripts are subsequently executed in the browser of any user (including administrators) who visits the affected page. The vulnerability is assigned a CVSS score of 6.5, reflecting that while it requires basic authentication and user interaction, it can lead to a partial impact on confidentiality, integrity, and availability. A fix is available in version 9.113.4.

Affected products

  • Hidekazu Ishikawa (Vektor, Inc.) VK All in One Expansion Unit <= 9.113.3

Timeline

  • 2026-02-21: other: Vulnerability reported by researcher timomangcut
  • 2026-03-23: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published to NVD
  • 2026-04-08: patched: Patch released in version 9.113.4

References