CVE-2026-102393: WordPress Starter Templates plugin <= 4.7.7 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Starter Templates astra-sites allows Stored XSS.This issue affects Starter Templates: from n/a through 4.7.7.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Starter Templatesto a version that resolves this vulnerability.Fixed in 4.7.8
Event History
Frequently Asked Questions
Which deployments should be treated as affected?
Deployments using the Brainstorm Force Starter Templates plugin are affected through version 4.7.7. The available data does not identify an earlier unaffected version.
What does an attacker need to exploit this issue?
The CVSS vector indicates network access, low-level privileges in the affected environment, and user interaction are required. The vulnerability is stored XSS, meaning attacker-controlled input can be retained and later rendered in a web page.
What is the expected impact if exploitation succeeds?
The CVSS metrics indicate low confidentiality, integrity, and availability impact, with a changed scope. The severity is rated medium with a CVSS score of 6.5.