Junglewise Threat Intelligence

CVE-2026-57337: PluginOps Landing Page Builder unauthenticated XSS

CVE-2026-57337 · Severity: high · CVSS 7.1 · Published 2026-06-29

Executive brief

Landing Page Builder is a WordPress plugin used to create and manage custom marketing pages. A security vulnerability allows unauthenticated attackers to inject malicious scripts into the website, which could lead to unauthorized redirects, theft of user session information, or the display of fraudulent content to visitors. This occurs when a victim interacts with a specially crafted link or page created by the attacker.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the PluginOps Landing Page Builder plugin for WordPress (versions <= 1.5.3.5) due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted page. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions. The issue is resolved in version 1.5.3.6.

Affected products

  • PluginOps Landing Page Builder <= 1.5.3.5

Timeline

  • 2026-04-21: other: Reported by researcher HaiND
  • 2026-06-29: disclosed: Vulnerability published by Patchstack and NVD
  • 2026-06-29: patched: Patch released in version 1.5.3.6

References