Executive brief
The Extra Settings for RocketChat plugin for WordPress, which adds configuration options for RocketChat integration, contains a security flaw that allows users with contributor-level access to inject malicious scripts into website pages. When other users or administrators visit these affected pages, the scripts will execute automatically in their browsers. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.
Technical details
The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the rxstg_shortcode() function. The vulnerability exists because the user-supplied 'title' attribute within the 'rocketchat' shortcode is concatenated directly into the HTML output. An authenticated attacker with contributor-level permissions or higher can exploit this by embedding malicious JavaScript in a post or page. When a site visitor views the compromised content, the script executes within the context of their session. This is tracked as CWE-79 and affects all versions up to 0.1.
Affected products
- WordPress Plugin Extra Settings for RocketChat up to, and including, 0.1
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory
References
- https://plugins.trac.wordpress.org/browser/extra-settings-for-rocketchat/trunk/rocketchat-extra-settings.php
- https://plugins.trac.wordpress.org/browser/extra-settings-for-rocketchat/trunk/rocketchat-extra-settings.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/061eeba3-10ad-4272-9880-dc01d4368683?source=cve