SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-14835

MEDIUM · CVSS 6.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-30 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The SOGO Add Script to Individual Pages Header Footer WordPress plugin allows users with contributor-level access and above to inject unsanitized JavaScript into post headers and footers, posing a risk of cross-site scripting (XSS) attacks. This vulnerability can lead to unauthorized script execution in the browsers of administrators and visitors, potentially compromising site integrity and user data. WordPress site administrators and developers should prioritize this issue to mitigate the risk of exploitation.

CVE
CVE-2026-14835
Severity
MEDIUM
CVSS
6.8
EPSS
0.24%
WordPress Java

Original NVD Description

The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict them to users with the unfiltered_html capability, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any administrator who reviews the post and of any visitor once the post is published.