Junglewise Threat Intelligence

CVE-2026-65528: bannersky BSK PDF Manager Cross Site Scripting

CVE-2026-65528 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Executive brief

BSK PDF Manager is a WordPress plugin used to manage and display PDF documents on websites. A security vulnerability allows users with 'Contributor' level access to inject malicious scripts into the site. If an administrator or visitor views the affected content, these scripts could redirect users to malicious sites, steal session information, or display unauthorized advertisements.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the BSK PDF Manager plugin for WordPress (versions <= 3.8) due to improper neutralization of input during web page generation (CWE-79). An attacker with 'Contributor' level privileges can inject arbitrary JavaScript payloads into the application. The vulnerability requires a privileged user (such as an administrator) to interact with the malicious content for the script to execute in their browser context. This can lead to session hijacking, unauthorized redirects, or modification of site content. As of the advisory date, no official patch has been released.

Affected products

  • bannersky BSK PDF Manager <= 3.8

Timeline

  • 2026-06-10: other: Vulnerability reported by researcher luc
  • 2026-07-23: disclosed: Advisory published by Patchstack and NVD

References