CVE-2026-13253: Ultimate Post WordPress Plugin Stored XSS in Advanced Search Block
Ultimate Post, a WordPress plugin, contains a stored cross-site scripting (XSS) vulnerability in its Advanced Search block feature. Authenticated users with contributor-level permissions or higher can embed malicious scripts into page content through the 'moreResultsText' attribute. When other users view an affected page, those scripts execute in their browsers, potentially compromising their accounts or session data. The vulnerability exists in plugin versions up to 5.0.31 and requires contributor access to exploit, which limits but does not eliminate risk in multi-author WordPress environments.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.4 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Weaknesses (CWE)
- CWE-79
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-09 / 2026-07-09
NVD description (verbatim)
The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attribute of the ultimate-post/advanced-search block in versions up to and including 5.0.31. This is due to insufficient input sanitization and output escaping in the Advanced_Search::content() render callback: the attribute value is filtered with wp_kses(), which strips disallowed HTML tags but does NOT escape HTML special characters such as double quotes in plain text, and the result is then concatenated directly into the data-viewmoretext HTML attribute without esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
8 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability resides in the Advanced_Search::content() method where the 'moreResultsText' block attribute undergoes insufficient output handling. The code applies wp_kses() to strip disallowed HTML tags but does not escape HTML special characters, particularly double quotes. The unescaped value is then directly concatenated into an HTML attribute (data-viewmoretext) without using esc_attr(). This allows an attacker to break out of the attribute context and inject arbitrary JavaScript. The flaw combines inadequate input sanitization with missing output encoding, violating WordPress security best practices for dynamic attribute injection.
Business impact
Organizations running Ultimate Post are exposed to persistent script injection attacks exploitable by staff with contributor access or higher. Attackers could steal session cookies, perform unauthorized actions on behalf of compromised users, redirect visitors to malicious sites, or deface content. The risk scales with the size of the editorial team and the sensitivity of account privileges in the WordPress installation. Websites handling sensitive data or serving authentication-required resources face elevated exposure.
Affected systems
Ultimate Post plugin for WordPress versions 5.0.31 and below. The vulnerability requires an authenticated attacker with contributor-level or administrator permissions. Self-hosted WordPress installations and managed WordPress hosting platforms using this plugin are affected. Multisite WordPress deployments where contributors can edit pages are of particular concern.
Exploitability
Exploitation requires valid WordPress credentials at contributor level or above; unauthenticated remote exploitation is not possible. However, contributor access is commonly granted to content authors and editors in typical WordPress deployments. No special tools or advanced techniques are needed—the attack can be crafted through the WordPress block editor interface. The lack of CVSS exploitation complexity (AC:L) and network accessibility (AV:N) reflect that the barrier to execution is primarily authentication, which is often available in multi-user environments.
Remediation
Update Ultimate Post to a version incorporating proper output escaping of the 'moreResultsText' attribute using esc_attr(). Verify the specific patched version against the plugin vendor's advisory and release notes. Until patching, restrict contributor-level access to trusted personnel only, audit existing pages for suspicious block configurations, and consider disabling the Advanced Search block feature if not actively used.
Patch guidance
Check the Ultimate Post plugin repository or vendor website for available updates addressing CVE-2026-13253. Apply the patch through WordPress's built-in plugin update mechanism. After updating, verify the plugin version in Settings > Plugins and conduct a test on a staging environment to confirm compatibility with active themes and other plugins. Review your site's backup and recovery procedures before applying to production.
Detection guidance
Search your WordPress database and pages for instances of the ultimate-post/advanced-search block with suspicious or suspicious-looking 'moreResultsText' values, particularly those containing HTML entities or script tags. Monitor contributor and editor user activity logs for unusual page modifications. Inspect the raw page content (HTML source or database queries) for unexpected JavaScript in data-viewmoretext attributes. Web application firewalls (WAF) configured for XSS patterns may flag exploitation attempts targeting this attribute.
Why prioritize this
Although the CVSS score is MEDIUM (6.4), the vulnerability poses meaningful risk because it enables persistent injection into public-facing content and requires only contributor-level access, a privilege frequently held by multiple staff members. The threat model applies broadly across WordPress sites using this popular plugin. Organizations should prioritize patching in multi-author environments or those with less-trusted contributor populations. Standalone or tightly-controlled sites with very few editors should still patch, but may schedule it as routine maintenance rather than emergency response.
Risk score, explained
The CVSS 3.1 score of 6.4 (MEDIUM) reflects: network-based attack vector (AV:N) with low attack complexity (AC:L), requiring authentication (PR:L) but no user interaction (UI:N), and a scope change (S:C) that allows impact across security domains. The score credits confidentiality and integrity impacts (C:L, I:L) but no availability impact (A:N). The privileged access requirement (contributor-level) prevents a higher severity rating, but the widespread presence of this plugin and the commonality of multi-author WordPress setups mean real-world risk justifies prioritization.
Frequently asked questions
Can unauthenticated users exploit this vulnerability?
No. The vulnerability requires valid WordPress credentials with contributor level access or above. Unauthenticated site visitors cannot inject the malicious payload, though they can execute it once injected by an authenticated attacker.
How do I know if my Ultimate Post plugin is affected?
Check your WordPress admin panel under Plugins. If Ultimate Post is installed and the version is 5.0.31 or below, you are affected. Update to the latest version available from the plugin repository to resolve the issue.
What can an attacker accomplish with this vulnerability?
An attacker with contributor access can inject JavaScript that runs whenever another user views an affected page. Possible outcomes include session hijacking, credential theft, malware distribution, website defacement, or redirection to phishing sites.
If I have a one-author WordPress site, do I still need to patch?
Yes. Security best practice dictates patching all known vulnerabilities regardless of immediate exposure perception, to guard against future staff additions, compromised accounts, or plugin interactions you may not anticipate.
This analysis is provided for informational purposes and reflects the vulnerability description and CVSS scoring as of the published date. SEC.co does not guarantee patch availability or timing. Verify all patch version numbers and applicability against the official plugin vendor advisory before deployment. Organizations should conduct internal testing on non-production systems before applying patches to production environments. This document does not constitute legal, compliance, or liability advice. Refer to your organization's vulnerability management policy and the vendor's official security advisory for authoritative guidance. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2016-20070MEDIUMPrivilege Escalation & Stored XSS in WordPress Booking Calendar Contact Form 1.0.23
- CVE-2018-25384MEDIUMStored XSS in Wikidforum 2.20 Allows Authenticated Attackers to Inject Malicious Scripts
- CVE-2019-25731MEDIUMStored XSS in Zuz Music 2.1 Contact Form
- CVE-2019-25737MEDIUMStored XSS in Live Chat Unlimited 2.8.3 – Admin Session Compromise
- CVE-2019-25739MEDIUMGigToDo 1.3 Stored XSS Vulnerability in Proposal Descriptions
- CVE-2019-25742MEDIUMStored XSS in Zoner Real Estate WordPress Theme 4.1.1 – Admin Account Compromise Risk
- CVE-2019-25743MEDIUMWordPress Soliloquy Lite 2.5.6 Stored XSS Vulnerability
- CVE-2019-25744MEDIUMWordPress Popup Builder 3.49 Stored XSS Vulnerability – Exploit Prevention & Patch Guide