PT-2026-53047 · WordPress · Shariff

·

CVE-2026-9677

·

Published

2026-06-27

·

Updated

2026-06-29

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Shariff for WordPress versions prior to 1.0.12
Description The plugin fails to sanitize or escape the shariff infourl setting before it is output in the frontend HTML via the generateshariff() function. This flaw allows high-privilege users, such as administrators, to execute Stored Cross-Site Scripting (XSS) attacks, which occurs when a malicious script is permanently stored on the target server and served to other users. This is possible even in environments where the unfiltered html capability is disabled, such as in multisite setups.
Recommendations Update Shariff for WordPress to version 1.0.12 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-9677

Affected Products

Shariff