Back to overview

CVE-2026-9677

Description
The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it in the frontend HTML via the generateshariff() function, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Metadata

CVE ID
CVE-2026-9677
State
PUBLISHED
Assigner
WPScan
Reserved
2026-05-27 07:49 UTC
Published
2026-06-27 06:00 UTC
Last updated
2026-06-27 06:00 UTC
Vendor / Product
Unknown / Shariff for WordPress
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown Shariff for WordPress 0 ≤ 1.0.11
Weakness (CWE)
CWESourceDescription
cna CWE-79 Cross-Site Scripting (XSS)
Back to overview