Executive brief
The Anomify AI plugin for WordPress, which provides anomaly detection and alerting services, contains a security flaw that allows administrators to inject malicious scripts into the plugin settings. If exploited, these scripts could execute in the browser of any user visiting the settings page, potentially leading to unauthorized actions or data theft. This risk is primarily relevant in environments where multiple administrators are present or where an administrator account has been compromised.
Technical details
The Anomify AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to improper input sanitization and output escaping of the 'anomify_api_key' parameter. While the plugin uses sanitize_text_field() before saving the value via update_option(), this function does not encode double-quote characters. Furthermore, the stored value is later echoed directly into an HTML attribute context (value="...") without using esc_attr(). An authenticated attacker with administrator-level privileges can exploit this to inject arbitrary web scripts. These scripts will execute whenever a user accesses the plugin's settings page.
Affected products
- Anomify AI Anomify AI – Anomaly Detection and Alerting up to and including 0.3.6
Timeline
- 2026-05-20: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/anomify/tags/0.3.6/Anomify/Config.php
- https://plugins.trac.wordpress.org/browser/anomify/tags/0.3.6/Anomify/Wp/Admin.php
- https://plugins.trac.wordpress.org/browser/anomify/tags/0.3.6/Anomify/Wp/includes/admin_options.php
- https://plugins.trac.wordpress.org/browser/anomify/trunk/Anomify/Config.php
- https://plugins.trac.wordpress.org/browser/anomify/trunk/Anomify/Wp/Admin.php
- https://plugins.trac.wordpress.org/browser/anomify/trunk/Anomify/Wp/includes/admin_options.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/4036057c-0c43-4d9c-97db-4861d91a4daa?source=cve