WP eMember < 10.6.6 - Stored XSS in Blacklist via CSRF
Description
CSRF in WP eMember plugin ≤10.6.5 lets an attacker trick an admin into injecting stored XSS via the blacklist feature.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CSRF in WP eMember plugin ≤10.6.5 lets an attacker trick an admin into injecting stored XSS via the blacklist feature.
Vulnerability
The WP eMember WordPress plugin versions before 10.6.6 lack CSRF protection, input sanitisation, and output escaping in certain administrative features, specifically the blacklist functionality [1]. This makes the plugin susceptible to a stored cross-site scripting (XSS) attack that can be triggered through a CSRF request [1].
Exploitation
An attacker must first craft a malicious request that contains a JavaScript payload and lure an authenticated administrator into submitting it — for example, by clicking a crafted link or visiting a malicious page while logged into the WordPress admin [1]. No additional privileges beyond the logged-in admin session are required; the CSRF check deficiency allows the attacker to forge a request on behalf of the admin [1]. The stored payload becomes part of the plugin's blacklist settings and executes when the admin views the relevant page [1].
Impact
Successful exploitation results in stored XSS within the WordPress admin panel. The attacker can execute arbitrary JavaScript in the context of the admin's session, potentially leading to session hijacking, forced administrative actions, or further site compromise [1].
Mitigation
The vulnerability is fixed in version 10.6.6 of the WP eMember plugin [1]. All users should update to this version or later immediately. There is no published workaround for versions below 10.6.6 [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/00fcbcf3-41ee-45e7-a0a9-0d46cb7ef859/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.