CVE-2026-14835
Received Received - Intake

SOGO Add Script Plugin Stored Cross-Site Scripting

Vulnerability report for CVE-2026-14835, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-30

Last updated on: 2026-08-30

Assigner: WPScan

Description

The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict them to users with the unfiltered_html capability, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any administrator who reviews the post and of any visitor once the post is published.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-30
Last Modified
2026-08-30
Generated
2026-08-30
AI Q&A
2026-08-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored Cross-Site Scripting (XSS) vulnerability in the SOGO Add Script to Individual Pages Header Footer WordPress plugin. It allows users with contributor-level access or higher to inject malicious JavaScript code via the post metabox. The plugin does not sanitize or escape these script values, causing them to execute in the browsers of administrators reviewing the post and visitors once published.

Detection Guidance

Check if the SOGO Add Script to Individual Pages Header Footer WordPress plugin version 3.9 or below is installed. Review posts with custom header/footer scripts for suspicious JavaScript code. Inspect browser console logs for unexpected script executions on admin or visitor pages.

Impact Analysis

Attackers with contributor-level access or higher can inject malicious scripts that execute in the browsers of administrators and visitors. This could lead to theft of session cookies, account takeover, defacement of web pages, or redirection to malicious sites. Administrators reviewing posts are also at risk of unintentionally executing harmful scripts.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, violating GDPR's data protection principles and HIPAA's security requirements. If exploited, it may result in data breaches, unauthorized data access, or disclosure of sensitive information, potentially leading to legal penalties and compliance failures.

Mitigation Strategies

Update the SOGO Add Script to Individual Pages Header Footer plugin to the latest version. Remove or sanitize any custom scripts added via the plugin. Restrict contributor-level access to trusted users only. Monitor posts for unauthorized script changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14835. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart