Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-14835— SOGO Add Script to Individual Pages Header Footer <= 3.9 - Contributor+ Stored XSS via Post Metabox

Quick assessment

Affected
Unknown SOGO Add Script to Individual Pages Header Footer
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SOGO Add Script to Individual Pages Header Footer WordPress 插件(版本 ≤ 3.9)未对其从帖子元数据框中保存的自定义页眉/页脚脚本值进行清理或转义,也未将执行权限限制为拥有 能力的用户。这导致具有贡献者(contributor)及以上权限的用户可以存储 JavaScript 代码,这些代码会在任何审阅该帖子的管理员的浏览器中执行,并且在帖子发布后,也将在所有访问者的浏览器中执行。

AI Predicted 6.3 Difficulty: Moderate

Possible ATT&CK Techniques 2 AI

T1059.006 · Python T1059.007 · JavaScript
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-14835

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SOGO Add Script to Individual Pages Header Footer <= 3.9 - Contributor+ Stored XSS via Post Metabox
Source: CVE Program / CVE List V5
Vulnerability Description
The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict them to users with the unfiltered_html capability, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any administrator who reviews the post and of any visitor once the post is published.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown SOGO Add Script to Individual Pages Header Footer 0 ~ 3.9 -

II. Public POCs for CVE-2026-14835

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-14835

登录查看更多情报信息。

Security Blog Posts for CVE-2026-14835 (1)

Same Patch Batch · Unknown · 2026-08-30 · 7 CVEs total

CVE-2026-81660 Groundhogg < 4.5.13 - Unauthenticated Stored XSS via Web Form Dropdown/Radio Field
CVE-2026-81766 Really Simple Security < 9.8.0 - Multisite Subsite Admin+ Arbitrary Plugin Installation vi
CVE-2026-78364 MW WP Form < 5.1.6 - Editor+ Stored XSS via Inquiry Data List
CVE-2026-19722 WPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup
CVE-2026-76585 Customer Reviews for WooCommerce < 5.118.0 - Unauthenticated Stored XSS via 'comment' Para
CVE-2026-14307 Geotargeting WP < 3.5.6.2 - Reflected XSS

IV. Related Vulnerabilities

V. Comments for CVE-2026-14835

No comments yet


Leave a comment