Junglewise Threat Intelligence

CVE-2026-81754: WordPress The Vigilant plugin stored XSS via User-Agent header

CVE-2026-81754 · Severity: high · CVSS 7.2 · Published 2026-09-11

Vendors: Wordpress.

Executive brief

The Vigilant is a WordPress security plugin offering firewall, two-factor authentication, and vulnerability scanning features. The plugin fails to properly sanitize the User-Agent HTTP header during login attempts, allowing attackers to inject malicious scripts that execute for all users who visit the affected WordPress site. An attacker can deliver this payload passively—simply by making a failed login attempt with a crafted header—and does not require any special permissions or user interaction beyond the initial injection.

Technical details

The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the User-Agent header processing. The plugin does not properly sanitize or escape the User-Agent value when processing failed login attempts, allowing arbitrary JavaScript to be stored and later executed in the context of authenticated users' browsers. The attack vector is network-based and requires no authentication—any unauthenticated visitor can trigger a failed login with a malicious User-Agent header to inject the payload. Once stored, the payload persists and executes whenever any user accesses the affected pages. The vulnerability affects all versions up to and including 2.10.2; patched versions are expected to address the input sanitization and output escaping gaps.

Affected products

  • WordPress The Vigilant up to and including 2.10.2

Timeline

  • 2026-09-11: disclosed

References