Junglewise Threat Intelligence

CVE-2026-57762: Andrew Fiebert Simple URLs Author XSS

CVE-2026-57762 · Severity: medium · CVSS 5.9 · Published 2026-07-02

Executive brief

Simple URLs, a WordPress plugin used for managing and tracking outbound links, contains a security flaw that allows users with 'Author' privileges to inject malicious scripts into the website. If an administrator or another visitor views the affected area, these scripts could execute, potentially leading to unauthorized redirects, the display of fraudulent advertisements, or the theft of session information. While this requires an internal user to initiate the attack, it poses a risk to the integrity of the site and the security of its visitors.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Simple URLs plugin for WordPress (versions <= 151) due to improper neutralization of input during web page generation (CWE-79). The vulnerability allows an authenticated attacker with 'Author' level permissions to inject arbitrary JavaScript payloads into the application. Successful exploitation requires a victim (such as an administrator) to interact with the affected page or perform a specific action, leading to script execution in the context of the victim's browser. As of the advisory date, no official patch has been released.

Affected products

  • Andrew Fiebert Simple URLs <= 151

Timeline

  • 2026-02-05: disclosed: Reported by Jitlada
  • 2026-07-02: advisory: Published by Patchstack and NVD

References