CVE-2026-39071: WordPress Spiffy Plugin vulnerability
Published Aug 28, 2026
·Updated
WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contributor) can exploit this to redirect user to malicious site or control the account.
Affected Software
1 affected component
WordPress Spiffy Plugin<5.0.9
Event History
Aug 28, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which installations are affected?
WordPress sites using Spiffy Plugin versions before 5.0.9 are affected.
2
What access does an attacker need?
An attacker must be authenticated and have at least the Contributor role. They can use the Event Title field to store malicious script content.
3
What is the impact of successful exploitation?
The stored cross-site scripting issue can redirect users to a malicious site or enable control of an account.
4
What version should be used to remediate the issue?
Update Spiffy Plugin to version 5.0.9 or later.