Back to overview

CVE-2026-14234

Description
The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker to trick a logged-in administrator into writing arbitrary content, including a malicious script, into a post via a cross-site request, resulting in stored Cross-Site Scripting.

Metadata

CVE ID
CVE-2026-14234
State
PUBLISHED
Assigner
WPScan
Reserved
2026-06-30 12:50 UTC
Published
2026-07-29 06:00 UTC
Last updated
2026-07-29 06:00 UTC
Vendor / Product
Unknown / WOLF
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown WOLF 0 < 1.1.0
Weakness (CWE)
CWESourceDescription
cna CWE-79 Cross-Site Scripting (XSS)
cna CWE-352 Cross-Site Request Forgery (CSRF)
Back to overview