Junglewise Threat Intelligence

CVE-2026-8038: Faces of Users WordPress plugin stored XSS in facesofusers shortcode

CVE-2026-8038 · Severity: medium · CVSS 6.4 · Published 2026-05-20

Executive brief

The Faces of Users plugin for WordPress, which is used to display user profiles or avatars, contains a security flaw that allows users with basic contributor permissions to inject malicious scripts into website pages. When other users or administrators visit these affected pages, the hidden scripts will execute in their browsers. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.

Technical details

The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'default' attribute of the 'facesofusers' shortcode. An authenticated attacker with Contributor-level permissions or higher can exploit this by embedding malicious JavaScript within the shortcode on a post or page. Because the plugin fails to properly neutralize this input before it is stored and subsequently rendered, the script will execute in the context of any user's browser who views the page. This vulnerability affects all versions of the plugin up to and including 0.0.3.

Affected products

  • Faces of Users Faces of Users Up to, and including, 0.0.3

Timeline

  • 2026-05-20: disclosed: Initial disclosure of the vulnerability.

References