CVE-2026-97266: WordPress Virtue/Ascend/Pinnacle Toolkit plugin <= 4.9.12.1 - Cross Site Scripting (XSS) vulnerability
Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Virtue/Ascend/Pinnacle Toolkit pluginto a version that resolves this vulnerability.Fixed in 4.9.12.2
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The issue is described as contributor XSS, so an attacker needs Contributor-level access to a WordPress site using an affected version of the plugin. Exploitation also requires user interaction, as reflected by the UI:R vector.
Which installations are affected?
Kadence Themes Virtue/Ascend/Pinnacle Toolkit versions 4.9.12.1 and earlier are identified as affected. The provided information does not state whether any particular plugin configuration or default setting is required.
What impact can successful exploitation have?
The CVSS vector indicates low impacts to confidentiality, integrity, and availability, with scope changed. Because this is XSS, successful exploitation can cause script execution in a victim's browser after they interact with attacker-controlled content.