Executive brief
The Post Snippets plugin for WordPress, which allows users to create and manage reusable content fragments, is vulnerable to a security flaw in its import feature. An attacker with administrative privileges could upload a malicious file that injects harmful scripts into the website's management interface. This could allow the attacker to perform unauthorized actions or steal information when other administrators use the post editor. This issue primarily affects multi-site WordPress installations where administrative permissions are more restricted.
Technical details
The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient output escaping in the `jqueryUiDialog()` method within `WPEditor.php`. Specifically, snippet content is embedded directly into JavaScript string literals without escaping double quotes, as the relevant escaping code was commented out. When snippets are imported via the Import/Export feature, they bypass the standard `wp_magic_quotes()` protection. An authenticated attacker with Administrator-level access can exploit this by importing a malicious file containing crafted snippets. These scripts execute in the context of any administrator accessing the post editor. This vulnerability specifically impacts multi-site environments where administrators do not inherently possess the `unfiltered_html` capability. The issue is addressed in version 4.1.1.
Affected products
- Post Snippets Post Snippets up to, and including, 4.0.19
Timeline
- 2026-05-29: disclosed
- 2026-05-29: advisory
References
- https://plugins.trac.wordpress.org/browser/post-snippets/tags/4.0.19/src/PostSnippets/DBTable.php
- https://plugins.trac.wordpress.org/browser/post-snippets/tags/4.0.19/src/PostSnippets/WPEditor.php
- https://plugins.trac.wordpress.org/browser/post-snippets/tags/4.1.1/src/PostSnippets/WPEditor.php
- https://plugins.trac.wordpress.org/browser/post-snippets/tags/4.1.1/src/PostSnippets/WPEditor.php
- https://plugins.trac.wordpress.org/browser/post-snippets/tags/4.1.1/src/PostSnippets/WPEditor.php
- https://plugins.trac.wordpress.org/browser/post-snippets/trunk/src/PostSnippets/DBTable.php
- https://plugins.trac.wordpress.org/browser/post-snippets/trunk/src/PostSnippets/WPEditor.php