Junglewise Threat Intelligence

CVE-2026-8698: WordPress Cryptocurrency Prijsvergelijking Widget Stored XSS

CVE-2026-8698 · Severity: medium · CVSS 6.4 · Published 2026-05-27

Vendors: Wordpress.

Executive brief

The Cryptocurrency Prijsvergelijking Widget plugin for WordPress, which allows site owners to display cryptocurrency price comparisons, contains a security flaw that allows for stored cross-site scripting. An attacker with basic contributor-level access can inject malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Cryptocurrency Prijsvergelijking Widget plugin for WordPress (v1.0) within the as_get_coin_shortcode() function. The vulnerability is caused by the failure to use escaping functions like esc_attr() when rendering 'width' and 'height' shortcode attributes into the style attribute of an <iframe> element. An attacker can provide a crafted value that prematurely terminates the style attribute and injects additional HTML attributes, such as 'onload'. This allows authenticated users with contributor-level permissions or higher to embed malicious JavaScript that executes in the context of any user viewing the compromised page.

Affected products

  • WordPress Cryptocurrency Prijsvergelijking Widget 1.0

Timeline

  • 2026-05-27: disclosed: Vulnerability published to NVD via Wordfence.
  • 2026-05-27: advisory

References