Junglewise Threat Intelligence

CVE-2026-6174: CC Child Pages Stored XSS via more parameter

CVE-2026-6174 · Severity: medium · CVSS 6.4 · Published 2026-05-14

Executive brief

The CC Child Pages plugin for WordPress, which is used to display lists of sub-pages on a website, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into website pages. These scripts will run automatically whenever a visitor views the affected page, potentially leading to unauthorized actions or data theft.

Technical details

The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'more' parameter. This vulnerability exists in all versions up to and including 2.1.1. An authenticated attacker with Contributor-level permissions or higher can inject arbitrary web scripts into the 'more' parameter, which are then stored on the server. These scripts execute in the context of a user's browser whenever they visit the compromised page. The vulnerability is tracked as CWE-79 and has been addressed in subsequent updates.

Affected products

  • Caterham Computing CC Child Pages up to, and including, 2.1.1

Timeline

  • 2026-05-14: disclosed
  • 2026-05-14: advisory

References