Juicer < 1.11 - Contributor+ Stored XSS
Description
The Juicer WordPress plugin before 1.11 has a stored XSS vulnerability via unsanitized shortcode attributes, allowing contributor+ users to inject arbitrary scripts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The Juicer WordPress plugin before 1.11 has a stored XSS vulnerability via unsanitized shortcode attributes, allowing contributor+ users to inject arbitrary scripts.
Vulnerability
The Juicer WordPress plugin versions before 1.11 fail to validate and escape shortcode attributes before outputting them in a page or post where the shortcode is embedded [1]. This allows users with the contributor role and above to inject arbitrary HTML and JavaScript via crafted shortcode attributes. Affected versions: all versions prior to 1.11.
Exploitation
An attacker with contributor-level access or higher can create or edit a post/page containing the vulnerable shortcode with malicious attribute values. No additional privileges or user interaction beyond the attacker's own actions are required. The injected script will be stored and executed when any user views the affected page.
Impact
Successful exploitation leads to Stored Cross-Site Scripting (XSS), enabling the attacker to execute arbitrary JavaScript in the context of the victim's browser. This can result in session hijacking, defacement, or redirection to malicious sites. The attack is persistent and affects all visitors to the compromised page.
Mitigation
The vulnerability is fixed in version 1.11 of the Juicer plugin [1]. Users should update to version 1.11 or later immediately. No workarounds are documented. The plugin is not listed on CISA's Known Exploited Vulnerabilities catalog as of publication.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- WordPress/Juicerdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/c8982b8d-985f-4a5d-840d-e8be7c3405bdmitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.