PT-2026-103042 · WordPress · Content Egg

·

CVE-2026-92424

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Content Egg WordPress plugin versions prior to 11.9.0
Description The bulk content-import feature fails to verify if the user is authorized for the selected import preset. The plugin switches to the identity of the preset author before creating the post, which allows users with contributor-level access or higher to store unfiltered arbitrary web scripts under a privileged account. These scripts execute in the context of any user who subsequently views the content.
Recommendations Update Content Egg WordPress plugin to version 11.9.0 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92424

Affected Products

Content Egg