CVE-2026-56045
Deferred Deferred - Pending Action
Unauthenticated XSS in Automatic Plugin

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: Patchstack

Description
Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
patchstack wordpress_automatic_plugin to 3.135.1 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-56045 is a Cross Site Scripting (XSS) vulnerability found in the WordPress Automatic Plugin versions prior to 3.135.1.

This vulnerability allows attackers to inject malicious scripts into the website, which execute when visitors access the site.

Exploitation requires user interaction, such as clicking a malicious link or submitting a form, often initiated by a privileged user.

Impact Analysis

The vulnerability can be exploited to execute malicious scripts on affected websites, potentially leading to unauthorized redirects, display of unwanted advertisements, or other malicious actions.

Because it has a CVSS score of 7.1, it represents a moderately dangerous risk that could be used in mass campaigns targeting thousands of websites.

Successful exploitation requires user interaction but can compromise the integrity and security of the website and its visitors.

Detection Guidance

This vulnerability affects the WordPress Automatic Plugin versions prior to 3.135.1 and involves Cross Site Scripting (XSS) that requires user interaction such as clicking a malicious link or submitting a form.

Detection can involve checking the plugin version installed on your WordPress site to see if it is older than 3.135.1.

Since the vulnerability involves malicious script injection, monitoring web traffic for suspicious scripts or unexpected redirects could help detect exploitation attempts.

Specific commands are not provided in the available resources.

Mitigation Strategies

Immediate mitigation involves updating the WordPress Automatic Plugin to version 3.135.1 or later.

Alternatively, applying a Patchstack mitigation rule can protect against this vulnerability.

Using Patchstack tools to automate updates and protection is also recommended.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56045. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart