PT-2026-67006 · WordPress · Spectra Legacy
CVE-2026-10827
·
Published
2026-08-01
·
Updated
2026-08-01
CVSS v3.1
3.5
Low
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Spectra Legacy WordPress plugin versions prior to 2.20.0
Description
Insufficient validation and escaping of several block style attributes allow users with the Contributor role and above to inject arbitrary CSS into pages rendering the affected block. These injected styles are served to anonymous visitors and can be used to force external resource loads, deface or redress the page, or exfiltrate data via CSS attribute selectors. JavaScript execution is prevented as the script-tag breakout is removed by KSES (a WordPress security filter that sanitizes HTML).
Recommendations
Update Spectra Legacy WordPress plugin to version 2.20.0 or later.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spectra Legacy