Junglewise Threat Intelligence

CVE-2026-66617: PublishPress Series Cross-Site Scripting (XSS) in plugin

CVE-2026-66617 · Severity: medium · CVSS 6.5 · Published 2026-09-17

Technologies: PublishPress Series. Vendors: PublishPress.

Executive brief

PublishPress Series is a WordPress plugin used to organize and manage series of related posts. The vulnerability allows contributors and other privileged users to inject malicious JavaScript code into the site, which can then steal visitor data, hijack user accounts, or perform unauthorized actions on behalf of site visitors.

Technical details

This is a Contributor-level Stored Cross-Site Scripting (XSS) vulnerability in PublishPress Series versions 3.1.3 and earlier. The vulnerability exists due to improper input sanitization or output escaping in the plugin. Exploitation requires a user with Contributor privileges (or higher) to inject a malicious payload; however, successful attacks also depend on a victim (typically an administrator or editor) interacting with the compromised content, such as clicking a crafted link or visiting a malicious page. An attacker with contributor access can inject scripts that execute in the browsers of site visitors and administrators, leading to credential theft or account compromise. The vulnerability has been patched in version 3.1.4.

Affected products

  • PublishPress Series <= 3.1.3

Timeline

  • 2026-09-17: disclosed: Vulnerability published by Patchstack
  • 2026-09-17: patched: Fix available in version 3.1.4

References

Related threats