CVE-2026-86790: WP Highlight Box <= 1.0 - Contributor+ Stored XSS via highlight-box Shortcode
Published Sep 12, 2026
·Updated
The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
1 affected component
wordpress/wp-highlight-box<=1.0
Event History
Sep 12, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Which users could exploit this issue?
A user with the WordPress contributor role or any higher-privileged role could exploit it by supplying malicious values in affected highlight-box shortcode attributes.
2
Where would the malicious script execute?
The script could be stored in content and execute when a page containing the affected highlight-box shortcode is rendered in a visitor's browser.
3
What versions are affected?
WP Highlight Box versions through 1.0 are affected.