Junglewise Threat Intelligence

CVE-2026-57420: Netrr Author Box WP Lens Stored XSS in author-box-for-divi

CVE-2026-57420 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Executive brief

Netrr Author Box WP Lens is a WordPress plugin used to display author profiles on websites. A security flaw in this plugin allows an attacker with basic user access to inject malicious scripts into the site. If a site visitor or administrator views the affected page, these scripts could redirect them to malicious websites, steal session information, or display unauthorized advertisements, potentially damaging the site's reputation and user security.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Netrr Author Box WP Lens plugin (slug: author-box-for-divi) through version 2.1.5. The issue stems from improper neutralization of user-supplied input during web page generation (CWE-79). An authenticated attacker with 'Subscriber' or higher privileges can inject malicious payloads into the database. These scripts are subsequently executed in the browser of any user (including administrators) who visits the affected page. The vulnerability requires minimal user interaction (viewing the page) and has been patched in version 2.1.6.

Affected products

  • Netrr Author Box WP Lens (author-box-for-divi) <= 2.1.5

Timeline

  • 2026-05-29: disclosed: Reported by ParkHyunWoo to Patchstack
  • 2026-07-08: advisory: Initial advisory published by Patchstack
  • 2026-07-13: patched: Version 2.1.6 released to address the vulnerability

References