CVE-2026-13701
Received Received - Intake

Stored XSS in Advanced Excerpt WordPress Plugin

Vulnerability report for CVE-2026-13701, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: WPScan

Description

The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it on the front end of the site, which could allow administrators (including those without the unfiltered_html capability, such as on multisite) to perform Stored Cross-Site Scripting attacks that execute in the context of any visitor viewing affected pages.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
advanced_excerpt advanced_excerpt to 4.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored Cross-Site Scripting (XSS) vulnerability in the Advanced Excerpt WordPress plugin before version 4.5. The plugin fails to sanitize and escape one of its settings before displaying it on the front end, allowing administrators to inject malicious scripts that execute when visitors view affected pages.

Detection Guidance

To detect this vulnerability, check the installed version of the Advanced Excerpt WordPress plugin. If the version is below 4.5, the system is vulnerable. You can verify the version by inspecting the plugin files or using WordPress admin panel under Plugins.

Impact Analysis

This vulnerability allows attackers with admin access to inject malicious scripts into web pages. When visitors view these pages, the scripts execute, potentially stealing cookies, session tokens, or other sensitive data. It can also be used to deface websites or redirect users to malicious sites.

Compliance Impact

This vulnerability could lead to data breaches, which may violate GDPR and HIPAA requirements for protecting user data. Organizations could face fines or penalties if they fail to address this issue and a breach occurs.

Mitigation Strategies

Immediately update the Advanced Excerpt plugin to version 4.5 or later. This patch addresses the improper sanitization and escaping flaw. Ensure backups are taken before updating. Monitor for any suspicious activity post-update.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13701. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart