Executive brief
The WP Latest Posts plugin for WordPress, which is used to display recent content in various layouts, contains a security flaw that allows users with author-level permissions to inject malicious scripts into website pages. These scripts execute automatically when other users, including site administrators, visit the affected pages. This could lead to unauthorized actions being performed on behalf of other users or the theft of sensitive session information.
Technical details
The WP Latest Posts plugin is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient output escaping in the field() and loop() functions within the wplp-front.inc.php file. These functions use regular expressions to extract raw 'src' attribute values from <img> tags in post content and then reconstruct new HTML elements or CSS background-image declarations by direct concatenation. This process bypasses WordPress's built-in kses filtering. An authenticated attacker with Author-level permissions or higher can exploit this by crafting a post with a malicious image source, leading to the execution of arbitrary JavaScript in the context of any user viewing the content. The vulnerability exists in all versions up to and including 5.0.11.
Affected products
- JoomUnited WP Latest Posts <= 5.0.11
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory
References
- https://plugins.trac.wordpress.org/browser/wp-latest-posts/tags/5.0.11/inc/wplp-front.inc.php
- https://plugins.trac.wordpress.org/browser/wp-latest-posts/tags/5.0.11/inc/wplp-front.inc.php
- https://plugins.trac.wordpress.org/browser/wp-latest-posts/tags/5.0.11/inc/wplp-front.inc.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/e00f69d6-df33-4179-843b-98f8ed034e4a?source=cve