← Retour aux CVEs
CVE-2026-2358
MEDIUM6.4
Description
The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[wp_ulike_likers_box]` shortcode `template` attribute in all versions up to, and including, 5.0.1. This is due to the use of `html_entity_decode()` on shortcode attributes without subsequent output sanitization, which effectively bypasses WordPress's `wp_kses_post()` content filtering. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The post must have at least one like for the XSS to render.
Details CVE
Score CVSS v3.16.4
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie3/11/2026
Derniere modification3/11/2026
Sourcenvd
Observations honeypot0
Faiblesses (CWE)
CWE-79
References
https://github.com/Alimir/wp-ulike/commit/3dcce696ea251b3733448332cc167e03b2a17c12(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/wp-ulike/trunk/includes/functions/general.php#L375(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/wp-ulike/trunk/includes/functions/utilities.php#L226(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/wp-ulike/trunk/includes/functions/utilities.php#L251(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/wp-ulike/trunk/includes/hooks/shortcodes.php#L209(security@wordfence.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.