Executive brief
TrustedSite is a WordPress plugin that provides site security and trustworthiness features. The plugin contains an unauthenticated cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into affected websites. This can lead to theft of visitor data, account hijacking, and defacement, potentially damaging customer trust and website reputation.
Technical details
The vulnerability is a reflected or stored cross-site scripting (XSS) flaw in TrustedSite plugin versions 1.2.5 and earlier that does not require authentication to exploit. The affected component fails to properly sanitize user-supplied input before rendering it in the web interface. An attacker can deliver a crafted URL or payload to trigger script execution in the browsers of site visitors, leading to session hijacking, credential theft, or malware distribution. The vulnerability has been patched in version 1.2.6 and later.
Affected products
- TrustedSite TrustedSite <= 1.2.5
Timeline
- 2026-09-02: disclosed
- 2026-09-02: patched: version 1.2.6