Executive brief
The SponsorMe plugin for WordPress, which is used to manage sponsorships, contains a security flaw that allows attackers to run malicious scripts in a user's browser. To exploit this, an attacker must trick a site visitor or administrator into clicking a specially crafted link. If successful, the attacker could potentially steal session information or perform unauthorized actions on behalf of the victim.
Technical details
The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping of the PHP_SELF parameter. The vulnerability exists within a function where the PHP_SELF value is reflected in both a form action attribute and an anchor href attribute. An unauthenticated attacker can exploit this by appending a crafted payload to the wp-admin/admin.php URL path. Successful exploitation requires user interaction, such as clicking a malicious link, and allows the execution of arbitrary JavaScript in the context of the victim's browser session. All versions up to and including 0.5.2 are affected.
Affected products
- WordPress SponsorMe up to, and including, 0.5.2
Timeline
- 2026-05-20: advisory: NVD publication date