CVE-2026-84899
Received Received - Intake

Vulnerable VikWidgetsLoader WordPress Plugin Stored Cross-Site Scripting

Vulnerability report for CVE-2026-84899, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: WPScan

Description

The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who reviews the pending submission.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
vikwidgets vikwidgetsloader to 1.12.0 (exc)
vikwidgetsloader vikwidgetsloader to 1.12.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The VikWidgetsLoader WordPress plugin before version 1.12.0 has a stored cross-site scripting (XSS) vulnerability. It fails to sanitize or escape a block attribute before outputting it in an inline script. This allows users with the Contributor role to inject arbitrary JavaScript that executes in the browsers of anyone viewing the affected post, including administrators.

Detection Guidance

To detect this vulnerability, check the installed version of the VikWidgetsLoader plugin in your WordPress site. If the version is below 1.12.0, the system is vulnerable. You can verify this via the WordPress admin dashboard under Plugins or by inspecting the plugin files directly.

Impact Analysis

This vulnerability allows attackers with Contributor-level access to inject malicious scripts into posts. When other users, including administrators, view these posts, the injected scripts execute in their browsers. This could lead to theft of session cookies, account takeover, or defacement of the website.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by enabling unauthorized access to user data through malicious scripts. GDPR requires protection of personal data, and HIPAA mandates safeguards for protected health information. A successful XSS attack may result in data breaches, triggering regulatory penalties and legal consequences.

Mitigation Strategies

Immediately update the VikWidgetsLoader plugin to version 1.12.0 or later. If updating is not possible, consider disabling the plugin temporarily until an update is applied. Regularly review user roles and permissions to ensure only trusted users have Contributor access or higher.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84899. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart