Executive brief
The Virtue/Ascend/Pinnacle Toolkit plugin for WordPress is vulnerable to a security flaw that allows users with 'Contributor' level access to inject malicious scripts into website pages. If a site administrator or visitor views the affected content, these scripts could execute, potentially leading to unauthorized redirects, the display of fraudulent advertisements, or the theft of session information. This risk is particularly relevant for sites that allow multiple users to draft or submit content.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Virtue/Ascend/Pinnacle Toolkit plugin for WordPress due to improper neutralization of input during web page generation (CWE-79). The flaw allows authenticated attackers with 'Contributor' level permissions or higher to inject arbitrary web scripts. These scripts are executed in the browser of any user (including administrators) who visits the page where the malicious payload is stored. Exploitation requires the attacker to have network access to the WordPress dashboard and necessitates some level of user interaction, such as a victim viewing the compromised post or page. The issue is resolved in version 4.9.12.1.
Affected products
- Nexcess (Liquid Web / StellarWP) Virtue/Ascend/Pinnacle Toolkit <= 4.9.12
Timeline
- 2026-07-14: disclosed: Reported by Ananda Dhakal via Patchstack
- 2026-07-22: advisory: Patchstack published advisory
- 2026-07-23: advisory: NVD published CVE record
- 2026-07-23: patched: Version 4.9.12.1 released to address the vulnerability