Junglewise Threat Intelligence

CVE-2026-81765: Tailored Tools XSS vulnerability in WordPress plugin

CVE-2026-81765 · Severity: high · CVSS 7.1 · Published 2026-08-31

Executive brief

Tailored Tools is a WordPress plugin used by website developers to extend website functionality. Versions up to 3.0.2 contain an unauthenticated cross-site scripting (XSS) flaw that allows attackers to inject malicious scripts into websites. An attacker could exploit this to steal visitor data, hijack user accounts, or deface website content without needing to authenticate.

Technical details

The vulnerability is a reflected or stored cross-site scripting (XSS) flaw in the Tailored Tools WordPress plugin versions 3.0.2 and earlier that requires no authentication to trigger. The root cause involves insufficient input sanitization or output encoding in the plugin's code. An attacker can craft a malicious link or page containing injected JavaScript that executes in the context of the affected website when a user visits or interacts with the payload. The vulnerability was patched in version 3.0.3. Patchstack has issued a mitigation rule to block exploitation attempts pending plugin updates.

Affected products

  • Tailored Media Tailored Tools <= 3.0.2

Timeline

  • 2026-08-28: disclosed
  • 2026-08-31: advisory: CVE-2026-81765 published on NVD
  • 2026-08-28: patched: Patch available in version 3.0.3

References