CVE-2026-17010: Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta
Published Aug 10, 2026
·Updated
The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing users with contributor-level access and above to inject stored Cross-Site Scripting payloads that execute in the browser of a higher-privileged user who reviews the content.
Affected Software
1 affected component
WordPress Saitama Addon Pack<=1.0.8
Event History
Aug 10, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-17010?
CVE-2026-17010 has a risk rating of 32.
2
How do I fix CVE-2026-17010?
To fix CVE-2026-17010, update the Saitama Addon Pack plugin to a version higher than 1.0.8.
3
What type of vulnerability is CVE-2026-17010?
CVE-2026-17010 is a stored Cross-Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2026-17010?
CVE-2026-17010 affects users with contributor-level access or higher in WordPress.
5
What is the impact of CVE-2026-17010?
The impact of CVE-2026-17010 is that it allows the injection of malicious scripts that execute in the browser of higher-privileged users.