Junglewise Threat Intelligence

CVE-2026-39708: uicore UiCore Elements Stored XSS

CVE-2026-39708 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Executive brief

UiCore Elements is a WordPress plugin used to add design elements and functionality to websites. A security flaw in this plugin allows an attacker with basic contributor-level access to inject malicious scripts into web pages. When other users or administrators visit these pages, the scripts could execute, potentially leading to unauthorized actions, website defacement, or the theft of sensitive session information.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the uicore UiCore Elements plugin for WordPress (versions <= 1.3.14). The issue stems from improper neutralization of user-supplied input during web page generation. An attacker with 'Contributor' level privileges or higher can inject malicious scripts into the site's database. These scripts are then executed in the browser of any user who views the affected content. The vulnerability has a CVSS score of 6.5, requiring network access and user interaction, but it allows for scope jumping (S:C), meaning the attacker can impact the security of the user's browser environment beyond the plugin itself.

Affected products

  • uicore UiCore Elements <= 1.3.14

Timeline

  • 2026-01-30: disclosed: Vulnerability reported by Abu Hurayra
  • 2026-03-01: advisory: Patchstack published advisory
  • 2026-04-08: advisory: CVE published to NVD

References