CVE-2026-88788
Received Received - Intake

Text Styler WordPress Plugin Stored Cross-Site Scripting

Vulnerability report for CVE-2026-88788, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: WPScan

Description

The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before outputting them within a front-end style block, and does not verify that a user may edit the target post, allowing users with contributor-level access or above to store JavaScript that executes in the browser of anyone viewing the affected post, including administrators.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored Cross-Site Scripting (XSS) vulnerability in the Text Styler WordPress plugin versions up to 1.1.1. It allows users with contributor-level access or higher to inject malicious JavaScript into posts by exploiting un-sanitized styling values. The injected script executes when the post is viewed by anyone, including administrators.

Detection Guidance

Check if the Text Styler WordPress plugin version 1.1.1 or below is installed. Inspect front-end style blocks for unsanitized user-supplied values or JavaScript code. Review post edit permissions for contributors and above.

Impact Analysis

If you use the affected plugin, attackers with contributor access could inject malicious scripts into your posts. These scripts could steal cookies, session tokens, or sensitive data, redirect users to malicious sites, or perform actions on behalf of users. Administrators viewing compromised posts risk complete account compromise.

Compliance Impact

This vulnerability could lead to data breaches, exposing user data and violating GDPR's integrity and confidentiality requirements. For HIPAA, it risks unauthorized access to protected health information. Both standards require safeguards against such exploits, and failure to address this could result in non-compliance penalties.

Mitigation Strategies

Update the Text Styler plugin to the latest version. Remove or disable the plugin if no update is available. Restrict contributor-level access to trusted users only. Monitor posts for unauthorized JavaScript injections.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88788. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart