Executive brief
The Contextual Related Posts plugin for WordPress improperly sanitizes user input in block parameters, allowing authenticated authors to inject malicious scripts into pages. When other users view these pages, the scripts execute in their browsers, potentially leading to account compromise or data theft.
Technical details
The plugin fails to sanitize and escape the 'other_attributes' block parameter, enabling authenticated attackers with author-level permissions to perform stored cross-site scripting attacks. The injected scripts persist in the page content and execute in the context of any user who accesses the affected page, bypassing client-side protections.
Affected products
- Contextual Related Posts Contextual Related Posts up to and including 4.4.1
Timeline
- 2026-09-22: disclosed