Executive brief
The SP Blog Designer plugin for WordPress, which is used to create custom blog layouts and carousels, contains a security flaw that allows users with basic contributor permissions to inject malicious scripts into website pages. When other users or administrators visit these affected pages, the hidden scripts will execute in their browsers. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.
Technical details
The SP Blog Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'design' attribute of the `wpsbd_post_carousel` shortcode. This vulnerability exists in all versions up to and including 1.0.0. An authenticated attacker with Contributor-level permissions or higher can exploit this by embedding malicious JavaScript within the shortcode attribute. When a user views the page where the shortcode is rendered, the script executes in the context of their session. This can be used to hijack administrative sessions or perform unauthorized actions on the site.
Affected products
- SP Blog Designer SP Blog Designer <= 1.0.0
Timeline
- 2026-05-12: disclosed: Initial disclosure of the vulnerability.
- 2026-05-12: advisory: NVD publication date.
References
- https://plugins.trac.wordpress.org/browser/sp-blog-designer/tags/1.0.0/includes/shortcode/wpsbd-post-carousel.php
- https://plugins.trac.wordpress.org/browser/sp-blog-designer/trunk/includes/shortcode/wpsbd-post-carousel.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/705b1da0-df92-40c2-a608-ccad32a9c224?source=cve