Junglewise Threat Intelligence

CVE-2026-57391: Tangible Loops & Logic Stored XSS in WordPress plugin

CVE-2026-57391 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Technologies: Tangible Loops & Logic. Vendors: Tangible.

Executive brief

Tangible Loops & Logic, a WordPress plugin used for creating dynamic content and custom templates, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. An attacker with basic user permissions (such as a subscriber) could save harmful code that executes when other users, including administrators, view specific pages. This could lead to unauthorized actions, theft of session information, or redirection of visitors to malicious websites.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Tangible Loops & Logic plugin for WordPress (versions <= 4.2.3) due to improper neutralization of user-supplied input during web page generation. The vulnerability allows an authenticated attacker with low-level privileges (Subscriber) to inject malicious scripts into the database. These scripts are subsequently executed in the context of a victim's browser (typically a more privileged user) when they interact with the affected content. The issue is addressed in version 4.2.4.

Affected products

  • Tangible Loops & Logic n/a through 4.2.3

Timeline

  • 2026-05-29: disclosed: Reported by ParkHyunWoo to Patchstack
  • 2026-07-08: advisory: Patchstack published advisory
  • 2026-07-13: advisory: NVD published CVE record
  • 2026-07-13: patched: Version 4.2.4 identified as patched version

References

Related threats