Junglewise Threat Intelligence

CVE-2026-39667: Jongmyoung Kim Korea SNS DOM-based XSS

CVE-2026-39667 · Severity: medium · CVSS 5.9 · Published 2026-04-08

Executive brief

Korea SNS is a WordPress plugin used to integrate South Korean social media sharing features into websites. A security vulnerability in this plugin allows an attacker with high-level permissions to inject malicious scripts into the site. If a site visitor or administrator interacts with a compromised page, the script could redirect users to malicious websites, display unauthorized advertisements, or steal session information.

Technical details

The Korea SNS plugin for WordPress (versions <= 1.7.0) contains a DOM-based Cross-Site Scripting (XSS) vulnerability due to improper neutralization of input during web page generation. An attacker with 'Author' or higher privileges can inject malicious scripts that execute in the context of a victim's browser. Exploitation requires user interaction, such as a privileged user visiting a specifically crafted page or clicking a malicious link. As of the advisory date, no official patch has been released by the vendor.

Affected products

  • Jongmyoung Kim Korea SNS <= 1.7.0

Timeline

  • 2026-01-19: other: Vulnerability reported by researcher Nabil Irawan
  • 2026-02-18: advisory: Initial advisory published by Patchstack
  • 2026-04-08: disclosed: CVE published to NVD

References