CVE-2025-26554
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nicola Mustone WP Discord Post wp-discord-post allows Reflected XSS.This issue affects WP Discord Post: from n/a through <= 2.1.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reflected XSS in WP Discord Post ≤2.1.0 allows attackers to inject malicious scripts via unvalidated input, enabling redirects, ads, or other payloads.
This reflected cross-site scripting (XSS) vulnerability in the WP Discord Post plugin for WordPress arises from improper neutralization of user-supplied input during web page generation. The plugin fails to sanitize or escape certain parameters before including them in HTTP responses, allowing an attacker to inject arbitrary HTML or JavaScript code [1].
The attack surface is a crafted URL containing the malicious payload. While the required privilege is low, successful exploitation requires user interaction — a victim with appropriate roles must click the malicious link, visit a crafted page, or submit a specially formed form. This makes the vulnerability suitable for mass-exploit campaigns targeting thousands of WordPress sites regardless of size or popularity [1].
An attacker exploiting this vulnerability can inject scripts that execute in the context of the victim's browser session. Potential impacts include redirecting visitors to malicious sites, displaying unwanted advertisements, stealing session cookies, or defacing the website. The CVSS v3 base score is 7.1 (High), and the vulnerability is rated moderately dangerous with exploitation expected [1].
Patchstack has issued a mitigation rule to block attacks until an official patch is available, tested, and safely applied. As immediate action, users should update the WP Discord Post plugin beyond version 2.1.0, or apply the provided mitigation if unable to update [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=2.1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.