CVE-2026-102376: WordPress Branda plugin <= 3.4.32 - Cross Site Scripting (XSS) vulnerability
Published Sep 30, 2026
·Updated
Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions.
Affected Software
1 affected component
WPMU DEV Branda<=3.4.32
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Branda White Labeling pluginto a version that resolves this vulnerability.Fixed in 3.4.33
Event History
Sep 30, 2026
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
WPMU DEV Branda versions 3.4.32 and earlier are affected.
2
What level of access does an attacker need?
The vulnerability is described as subscriber XSS, indicating that an attacker needs subscriber-level access. Exploitation also requires user interaction.
3
What is the potential impact?
Successful exploitation can affect confidentiality, integrity, and availability, each with low impact according to the supplied severity vector.