Executive brief
The Pochipp plugin for WordPress is a media search tool used by content creators. An unauthenticated attacker can inject malicious JavaScript through a specially crafted link that, when clicked by a site administrator or author, executes arbitrary code in their browser. This could allow attackers to steal session tokens, modify content, or perform administrative actions on the affected WordPress site.
Technical details
Reflected XSS vulnerability in the 'keyword' parameter due to insufficient output escaping. The vulnerable code reads $_GET['keyword'], applies only sanitize_text_field() which strips HTML tags but leaves double quotes intact, then directly interpolates the unsanitized value into an HTML attribute via PHP heredoc without using esc_attr(). The attack requires tricking a user with upload_files capability (Author or above) into clicking a malicious link to the media upload page.
Affected products
- Pochipp Pochipp up to and including 1.20.2
Timeline
- 2026-09-19: disclosed