CVE-2026-84816: WordPress WPCS plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability
Published Sep 10, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.
Affected Software
1 affected component
WPCS plugin<=1.3.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WPCS Pluginto a version that resolves this vulnerability.Fixed in 1.3.3
Event History
Sep 10, 2026
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
No authentication is required. The attack vector is network-accessible, but exploitation requires user interaction.
2
What impact can successful exploitation have?
The reported severity is high, with a CVSS score of 7.1. The vector indicates low impacts to confidentiality, integrity, and availability, and that the impact scope can extend beyond the vulnerable component.
3
Which plugin versions are affected?
WPCS versions 1.3.2 and earlier are identified as affected.