Executive brief
The ValvePress Automatic plugin for WordPress, which automates content posting from various sources, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could execute unauthorized actions, redirect users to malicious sites, or steal sensitive session information. This vulnerability can be exploited without needing a username or password, potentially impacting the site's reputation and user security.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the ValvePress Automatic plugin (wp-automatic) for WordPress in versions prior to 3.135.1. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted page. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized administrative actions if the victim is a privileged user. The issue is resolved in version 3.135.1.
Affected products
- ValvePress Automatic (wp-automatic) < 3.135.1
Timeline
- 2026-04-23: disclosed: Reported by Nguyen Ba Khanh
- 2026-06-25: advisory: Patchstack advisory published
- 2026-06-26: patched: NVD publication and patch availability confirmed in version 3.135.1