CVE-2026-92424
Received Received - Intake

Privilege Escalation via Content Import in Content Egg WordPress Plugin

Vulnerability report for CVE-2026-92424, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: WPScan

Description

The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary web scripts unfiltered under a privileged user's account, executing in the context of anyone who later views that content.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
keywordfinders content_egg to 11.9.0 (exc)
wp-plugins content_egg to 11.9.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored Cross-Site Scripting (XSS) flaw in the Content Egg WordPress plugin before version 11.9.0. It occurs because the plugin does not verify if a user running its bulk content-import feature is authorized for the selected import preset. The plugin switches to the preset author's identity before creating posts, allowing users with contributor-level access or higher to inject arbitrary scripts under a privileged user's account. These scripts execute when other users view the content.

Detection Guidance

Check if the Content Egg WordPress plugin version is prior to 11.9.0 using commands like 'wp plugin list' or by inspecting the plugin files in the WordPress installation directory. Look for unauthorized script injections in posts or pages, particularly those created via bulk content-import features.

Impact Analysis

If exploited, this vulnerability allows attackers to store malicious scripts on your WordPress site under a privileged user's account. When other users view the infected content, the scripts run in their browsers, potentially stealing session cookies, login credentials, or performing actions on their behalf. This could lead to unauthorized access, data theft, or defacement of your website.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by enabling unauthorized access to user data. GDPR requires protecting personal data, and HIPAA mandates safeguarding health information. If exploited, attackers could steal sensitive data, resulting in legal penalties, fines, or reputational damage for failing to meet these regulatory standards.

Mitigation Strategies

Update the Content Egg plugin to version 11.9.0 or later immediately. Review all posts and pages for unauthorized script injections, especially those created recently. Remove any suspicious scripts and restrict contributor-level access to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92424. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart