Junglewise Threat Intelligence

CVE-2026-4081: ZeM STL plugin for WordPress Stored XSS in [zemstl] shortcode

CVE-2026-4081 · Severity: medium · CVSS 6.4 · Published 2026-06-02

Executive brief

The ZeM STL plugin for WordPress, which is used to display 3D models on websites, contains a security flaw that allows users with basic posting privileges to inject malicious scripts into pages. When other users or administrators visit these affected pages, the hidden scripts can execute in their browsers. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.

Technical details

The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, the 'url', 'color', and 'bgcolor' parameters within the [zemstl] shortcode are directly interpolated into the HTML attribute context without being processed by escaping functions like esc_attr(). An authenticated attacker with Contributor-level permissions or higher can exploit this by crafting a shortcode with malicious payloads. When a site visitor or administrator views the page containing the shortcode, the injected script executes in their browser context. This vulnerability affects all versions of the plugin up to and including 1.0.

Affected products

  • ZeM STL ZeM STL plugin up to and including 1.0

Timeline

  • 2026-06-02: disclosed: CVE published by Wordfence/NVD

References