Executive brief
Sidebar Manager Light is a WordPress plugin that manages custom sidebars and widget areas. The plugin fails to properly sanitize user input in the 'sbm_description' parameter, allowing unauthenticated attackers to inject malicious JavaScript code into pages. When other users view affected pages, the injected scripts execute in their browsers, potentially compromising their accounts or stealing sensitive data.
Technical details
This is a Stored Cross-Site Scripting (XSS) vulnerability in the Sidebar Manager Light WordPress plugin affecting versions up to and including 1.18. The vulnerability exists in the 'sbm_description' parameter due to insufficient input sanitization and output escaping. The vulnerable code paths are in otw_list_sidebars.php and otw_process_actions.php. Unauthenticated attackers can inject arbitrary JavaScript that persists in the application and executes whenever users access injected pages. The CVSS v3.1 base score is 7.2, indicating high severity.
Affected products
- Open Themes Sidebar Manager Light up to and including 1.18
Timeline
- 2026-09-10: disclosed