VYPR
Medium severity6.5NVD Advisory· Published Mar 13, 2026· Updated Apr 22, 2026

CVE-2026-32403

CVE-2026-32403

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in toocheke Toocheke Companion toocheke-companion allows DOM-Based XSS.This issue affects Toocheke Companion: from n/a through <= 1.194.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Toocheke Companion <=1.194 has a DOM-based XSS vulnerability where unneutralized user input allows script injection requiring a privileged user interaction.

The Toocheke Companion plugin for WordPress versions up to and including 1.194 contains a DOM-based Cross-Site Scripting (XSS) vulnerability [1]. This arises from improper neutralization of input during web page generation, allowing attacker-controlled data to be executed as JavaScript in the browser of a victim visiting a crafted page [CVE description].

Exploitation requires a privileged user (such as an administrator or editor) to perform an action like clicking a malicious link, submitting a crafted form, or visiting a specially prepared page [1]. The attacker does not need direct network access to the vulnerable site but must socially engineer a user with appropriate privileges into triggering the payload.

Successful exploitation enables an attacker to inject arbitrary HTML and JavaScript into the context of the victim's session [1]. This could be used to redirect visitors, inject advertisements, or perform other client-side attacks that appear to originate from the trusted WordPress site, potentially affecting any guest who views the compromised page.

The vendor has released version 1.195 which addresses the vulnerability [1]. Users are strongly advised to update their plugin to this version immediately, or enable automatic updates for vulnerable plugins if using a Patchstack subscription [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.