PT-2026-96649 · WordPress · Text Styler

CVE-2026-88788

·

Published

2026-09-22

·

Updated

2026-10-02

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Text Styler versions prior to 1.1.2
Description The Text Styler WordPress plugin fails to sanitize and escape user-supplied styling values before they are output within a front-end style block. Additionally, the plugin does not verify if a user has permission to edit the target post. This allows users with contributor-level access or higher to perform a Stored Cross-Site Scripting (XSS) attack by storing JavaScript that executes in the browser of any user viewing the affected post, including administrators. Cross-Site Scripting (XSS) is a technique where malicious scripts are injected into trusted websites.
Recommendations Update the plugin to a version newer than 1.1.1.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88788

Affected Products

Text Styler