Junglewise Threat Intelligence

CVE-2026-8845: Islamic Database WordPress plugin Stored XSS in islamicDB-roqya shortcode

CVE-2026-8845 · Severity: medium · CVSS 6.4 · Published 2026-05-27

Executive brief

The Islamic Database plugin for WordPress, which provides religious content integration, contains a security flaw that allows users with contributor-level access to inject malicious scripts into website pages. These scripts execute automatically when other users, including site administrators, visit the affected pages. This could lead to unauthorized actions being performed on behalf of other users or the theft of sensitive session information.

Technical details

The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the islamicDB_sc_quran_qari_roqya() function. Specifically, the 'width' and 'height' attributes of the 'islamicDB-roqya' shortcode are concatenated directly into HTML iframe attribute values without being properly neutralized. An authenticated attacker with contributor-level permissions or higher can exploit this by crafting a shortcode with malicious payloads in these attributes. When the page is rendered, the script is stored and executed in the context of any user's browser who views the page. The vulnerability exists in versions up to and including 1.0.

Affected products

  • Islamic Database Islamic Database up to, and including, 1.0

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References