Junglewise Threat Intelligence

CVE-2026-53737: Juicer WordPress plugin stored XSS in admin settings page

CVE-2026-53737 · Severity: medium · CVSS 6.1 · Published 2026-06-10

Executive brief

Juicer is a WordPress plugin used to aggregate and display social media feeds from platforms like Instagram, Facebook, and LinkedIn. A security flaw allows an attacker who controls a connected social media feed to inject malicious scripts into the plugin's administrative settings page. If a site administrator views these settings, the script could execute in their browser, potentially leading to unauthorized actions or the compromise of the WordPress site.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Juicer WordPress plugin through version 1.12.18. The issue stems from the improper neutralization of input (CWE-79) where the plugin fails to sanitize or escape data retrieved from remote social media feed APIs before displaying it on the administrative settings page. An attacker capable of controlling the content of a connected feed (e.g., via a malicious social media post or a compromised API response) can inject JavaScript that executes in the context of a logged-in administrator. This requires the administrator to visit the specific settings page where the malicious feed data is rendered. As of the advisory date, users are advised to check for updates beyond version 1.12.18.

Affected products

  • Juicer.io Juicer.io (WordPress plugin) through 1.12.18

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory

References