CVE-2026-9577
Received Received - Intake

Reflected Cross-Site Scripting in Post Status Notifier Lite WordPress Plugin

Vulnerability report for CVE-2026-9577, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: WPScan

Description

The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in the administrator's session when they are tricked into following a crafted URL.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-23
AI Q&A
2026-07-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
post_status_notifier_lite post_status_notifier_lite to 1.13.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Reflected Cross-Site Scripting (XSS) vulnerability in the Post Status Notifier Lite WordPress plugin before version 1.13.0. It occurs because the plugin does not properly escape the `mod` URL parameter before displaying it in the admin settings page. An attacker can craft a malicious URL that, when clicked by an administrator, executes arbitrary JavaScript in the administrator's session.

Detection Guidance

Check if the Post Status Notifier Lite plugin version is below 1.13.0. Inspect URLs for the `mod` parameter in admin settings pages. Look for unusual admin session activity after clicking links.

Impact Analysis

If you are an administrator using the Post Status Notifier Lite plugin before version 1.13.0, an attacker could trick you into clicking a malicious link. This could allow the attacker to execute malicious scripts in your browser, potentially stealing session cookies, performing unauthorized actions, or taking control of your WordPress admin account.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR (data protection) or HIPAA (health information privacy). If exploited, it could result in data breaches, unauthorized modifications, or exposure of personal or health-related information, potentially leading to legal and regulatory penalties.

Mitigation Strategies

Update the Post Status Notifier Lite plugin to version 1.13.0 or later immediately. Avoid clicking untrusted links in admin emails or messages. Monitor admin accounts for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9577. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart