CVE-2026-88903: Topcontent <= 1.2.1 - Unauthenticated Stored XSS via Content Webhook
Published Oct 11, 2026
·Updated
The Topcontent WordPress plugin through 1.2.1 does not properly authorise one of its request handlers and disables HTML sanitisation before storing the submitted content, allowing unauthenticated attackers to publish arbitrary posts containing malicious JavaScript on any site where its API key has never been configured.
Affected Software
1 affected component
Topcontent Topcontent WordPress plugin<=1.2.1
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which sites are exposed to this issue?
Sites using the Topcontent WordPress plugin through version 1.2.1 are exposed when the plugin's API key has never been configured.
2
Does an attacker need an account or other authentication?
No. The vulnerable request handler can be used by unauthenticated attackers.
3
What can a successful attacker do?
An attacker can publish arbitrary posts containing malicious JavaScript. The script may then execute in the browsers of users who view the affected content.