CVE-2026-97270: WordPress CMB2 plugin <= 2.13.0 - Cross Site Scripting (XSS) vulnerability
Published Sep 30, 2026
·Updated
Subscriber Cross Site Scripting (XSS) in CMB2 <= 2.13.0 versions.
Affected Software
1 affected component
WordPress CMB2<=2.13.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress CMB2 pluginto a version that resolves this vulnerability.Fixed in 2.13.1
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is described as exploitable by a Subscriber, so the attacker needs a low-privileged authenticated WordPress account.
2
Does exploitation require someone else to interact with attacker-controlled content?
Yes. The CVSS vector includes UI:R, indicating that user interaction is required for exploitation.
3
What impact can successful exploitation have?
The listed CVSS impacts indicate low confidentiality, integrity, and availability impact, with scope changed. As an XSS issue, successful exploitation may allow attacker-supplied script to run in a victim's browser context.