PT-2026-51666 · WordPress · Ai Share & Summarize
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
AI Share & Summarize versions prior to 2.0.4
Description
Users with the Contributor role and above can perform Stored Cross-Site Scripting (XSS) attacks. This occurs because the plugin fails to sanitize and escape certain shortcode attributes, specifically the
title style attribute, before they are output on a page. Stored XSS is a type of vulnerability where a malicious script is permanently stored on the target server and executed in the browser of users who visit the affected page.Recommendations
Update AI Share & Summarize to version 2.0.4 or later.
As a temporary mitigation, restrict the use of the
title style shortcode attribute for users with the Contributor role.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ai Share & Summarize