VYPR
Medium severity6.5NVD Advisory· Published May 27, 2026

CVE-2026-49044

CVE-2026-49044

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advanced Custom Fields: Font Awesome Field allows Stored XSS.

This issue affects Advanced Custom Fields: Font Awesome Field: from n/a through 5.0.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Advanced Custom Fields: Font Awesome Field plugin up to v5.0.2 allows attackers to inject malicious scripts via unsanitized input.

Vulnerability

The Advanced Custom Fields: Font Awesome Field plugin for WordPress, versions from n/a through 5.0.2, contains a stored cross-site scripting vulnerability due to improper neutralization of input during web page generation [1]. The flaw resides in how the plugin handles user-supplied data for the Font Awesome field, allowing injection of arbitrary HTML and JavaScript [1].

Exploitation

To exploit this vulnerability, an attacker must be authenticated as a user with the ability to create or edit posts and include the Font Awesome field (e.g., Editor or Administrator role) [1]. The attacker injects malicious code into the field input; when an administrator or other privileged user views the post—such as by clicking a crafted link or visiting the dashboard page—the injected script executes in their browser [1]. The user action required is a visit to the affected page [1].

Impact

Successful exploitation allows the attacker to inject malicious scripts (e.g., redirects, advertisements, or other HTML payloads) that execute in the context of a victim's session when they visit the compromised site [1]. This can lead to session hijacking, defacement, or further compromise of the WordPress instance [1]. The CIA impact is primarily integrity and confidentiality, with the attacker operating within the scope of the affected user's privileges.

Mitigation

The vendor has not yet released a patched version of the plugin [1]. As an immediate workaround, disable the plugin or restrict access to the vulnerable field via user role capabilities [1]. If a fix becomes available in the future, update to the latest version promptly [1]. Users unable to update should contact their hosting provider or web developer for assistance [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.