Junglewise Threat Intelligence

CVE-2026-65538: Nilo Velez Machete XSS in WordPress plugin

CVE-2026-65538 · Severity: medium · CVSS 5.9 · Published 2026-07-23

Executive brief

Machete is a WordPress plugin designed to optimize and clean up website installations. A security vulnerability in versions 5.2 and earlier allows a user with Author-level permissions to inject malicious scripts into the website. If an administrator or another visitor views the affected content, these scripts could be used to redirect users to malicious sites, display unauthorized advertisements, or perform actions on behalf of the victim.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Machete plugin for WordPress (versions <= 5.2) due to improper neutralization of input during web page generation (CWE-79). The flaw allows a remote attacker with high privileges (Author role) to inject arbitrary web scripts. Exploitation requires a victim, such as a site administrator, to interact with the malicious content or perform a specific action (User Interaction). Successful exploitation can lead to the execution of scripts in the context of the victim's session, potentially allowing for data theft or unauthorized site modifications. As of the advisory date, no official patch has been confirmed.

Affected products

  • Nilo Velez Machete <= 5.2

Timeline

  • 2026-06-15: other: Vulnerability reported by researcher
  • 2026-07-23: disclosed: Vulnerability published by Patchstack and NVD

References