Executive brief
The GBI To Print plugin for WordPress, which provides printing functionality for website content, contains a security flaw that allows users with contributor-level access or higher to inject malicious scripts into pages. These scripts execute automatically whenever a visitor views the affected page, potentially leading to unauthorized actions or data theft. This vulnerability compromises the integrity of the website and can be used to target both site administrators and regular visitors.
Technical details
The GBI To Print plugin for WordPress (v1.0) is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient output escaping in the gbi_toprint_shortcode() function. The vulnerability exists because the 'div' attribute of the [gbitoprint] shortcode is concatenated directly into an HTML attribute without being passed through sanitization functions like esc_attr(). An authenticated attacker with at least contributor-level permissions can exploit this by creating a post with a malicious shortcode. When the post is viewed, the injected script executes in the context of the victim's browser, potentially allowing for session hijacking or administrative account takeover.
Affected products
- GBI To Print GBI To Print 1.0
Timeline
- 2026-05-27: disclosed: Initial publication of the CVE record.
- 2026-05-27: advisory: Wordfence published the vulnerability details.