Junglewise Threat Intelligence

CVE-2026-5508: WowPress WordPress plugin stored XSS in wowpress shortcode

CVE-2026-5508 · Severity: medium · CVSS 6.4 · Published 2026-04-08

Executive brief

The WowPress plugin for WordPress is vulnerable to a security flaw that allows users with basic contributor permissions to inject malicious scripts into website pages. When other visitors or administrators view these affected pages, the hidden scripts will run automatically in their browsers. This could lead to unauthorized actions being performed on behalf of other users or the theft of sensitive session information.

Technical details

The WowPress plugin for WordPress (versions up to 1.0.0) contains a Stored Cross-Site Scripting (XSS) vulnerability within its `wowpress` shortcode implementation. The root cause is insufficient input sanitization and output escaping of user-supplied attributes within the shortcode. An authenticated attacker with at least contributor-level privileges can exploit this by embedding malicious JavaScript into a post or page. Because the script is stored on the server, it executes in the context of any user's browser who views the compromised content, potentially allowing for session hijacking or unauthorized administrative actions. As of the advisory date, all versions up to 1.0.0 are affected.

Affected products

  • theyeti WowPress <= 1.0.0

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory

References