Executive brief
Post Status Notifier Lite is a WordPress plugin used to send notifications when post statuses change. A security flaw allows attackers to execute malicious scripts in the browser of a site administrator if the administrator clicks on a specially crafted link. This could lead to unauthorized actions being performed on the website or the theft of sensitive session information.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Post Status Notifier Lite plugin for WordPress due to insufficient sanitization of the 'mod' URL parameter. The vulnerable code reflects the parameter's value directly into the admin settings page (admin.php?page=post-status-notifier-lite) without proper escaping. An unauthenticated remote attacker can exploit this by tricking a logged-in administrator into clicking a malicious link. Successful exploitation allows the execution of arbitrary JavaScript in the context of the administrator's session, potentially leading to full site compromise. The issue is fixed in version 1.13.0.
Affected products
- Unknown Post Status Notifier Lite < 1.13.0
Timeline
- 2026-07-02: disclosed: Publicly published by WPScan
- 2026-07-23: advisory: NVD publication date
- 2026-07-02: patched: Fixed in version 1.13.0