Junglewise Threat Intelligence

CVE-2026-65527: Lqd LIQUID SPEECH BALLOON XSS in WordPress plugin

CVE-2026-65527 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Executive brief

LIQUID SPEECH BALLOON is a WordPress plugin used to display speech-bubble style content on websites. A security vulnerability allows users with 'Contributor' level access to inject malicious scripts into the site. If a site administrator or visitor views the affected content, these scripts could execute, potentially leading to unauthorized actions, website defacement, or redirection to malicious sites.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the LIQUID SPEECH BALLOON plugin for WordPress (versions <= 1.2.5) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an authenticated attacker with 'Contributor' level privileges to inject arbitrary JavaScript into the application. The attack requires a victim (such as an administrator) to interact with the malicious content or visit a crafted page for the script to execute in their browser context. This can lead to session hijacking or unauthorized administrative actions. As of the advisory date, no official patch has been released.

Affected products

  • lqd LIQUID SPEECH BALLOON <= 1.2.5

Timeline

  • 2026-06-08: disclosed: Reported by Ananda Dhakal via Patchstack
  • 2026-07-23: advisory: NVD and Patchstack published the vulnerability details

References