Executive brief
The KIA Subtitle plugin for WordPress, which allows site owners to add secondary titles to posts and pages, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into website pages. When other users or administrators visit these pages, the scripts execute, potentially leading to unauthorized actions or data theft.
Technical details
The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'before' and 'after' attributes of the 'the-subtitle' shortcode. This vulnerability allows authenticated attackers with Contributor-level permissions or higher to inject arbitrary web scripts into pages. These scripts are stored on the server and execute in the context of a user's browser whenever they access the affected page. The issue is present in all versions up to 4.0.1 and was addressed in version 4.0.2.
Affected products
- KIA Subtitle KIA Subtitle Up to, and including, 4.0.1
Timeline
- 2026-05-22: disclosed
- 2026-05-22: advisory
References
- https://plugins.trac.wordpress.org/browser/kia-subtitle/tags/4.0.1/kia-subtitle.php
- https://plugins.trac.wordpress.org/browser/kia-subtitle/tags/4.0.1/kia-subtitle.php
- https://plugins.trac.wordpress.org/browser/kia-subtitle/tags/4.0.2/kia-subtitle.php
- https://plugins.trac.wordpress.org/browser/kia-subtitle/tags/4.0.2/kia-subtitle.php
- https://plugins.trac.wordpress.org/browser/kia-subtitle/trunk/kia-subtitle.php
- https://plugins.trac.wordpress.org/browser/kia-subtitle/trunk/kia-subtitle.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a9a52097-0d85-4036-9b74-f35fea549607?source=cve