Executive brief
Tailored Tools is a WordPress plugin used by website developers to extend website functionality. Versions up to 3.0.2 contain an unauthenticated cross-site scripting (XSS) flaw that allows attackers to inject malicious scripts into websites. An attacker could exploit this to steal visitor data, hijack user accounts, or deface website content without needing to authenticate.
Technical details
The vulnerability is a reflected or stored cross-site scripting (XSS) flaw in the Tailored Tools WordPress plugin versions 3.0.2 and earlier that requires no authentication to trigger. The root cause involves insufficient input sanitization or output encoding in the plugin's code. An attacker can craft a malicious link or page containing injected JavaScript that executes in the context of the affected website when a user visits or interacts with the payload. The vulnerability was patched in version 3.0.3. Patchstack has issued a mitigation rule to block exploitation attempts pending plugin updates.
Affected products
- Tailored Media Tailored Tools <= 3.0.2
Timeline
- 2026-08-28: disclosed
- 2026-08-31: advisory: CVE-2026-81765 published on NVD
- 2026-08-28: patched: Patch available in version 3.0.3