CVE-2026-92712: ReactPress <= 3.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'permalink' Parameter
The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permalink' parameter in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the permalink parameter is only passed through sanitizeurl(), which does not prevent fetching attacker-controlled remote URLs whose response body — including script tags and event-handler attributes — is written verbatim to disk via fileputcontents().
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated WordPress user with at least Subscriber-level access can exploit it. The attacker must be able to submit a malicious value through the plugin's permalink parameter.
What must occur for the injected script to execute?
The attacker-controlled remote URL must be fetched, and its response content is written to disk without adequate sanitization or escaping. The stored script executes when a user visits the injected page.
Are sites affected if untrusted users can register as Subscribers?
Yes. Because Subscriber-level accounts meet the required privilege level, sites that allow untrusted users to obtain authenticated Subscriber access are exposed to exploitation by those users.
Which versions are affected?
All ReactPress versions up to and including 3.4.0 are affected.