PT-2026-26259 · WordPress · Info Cards – Add Text/Media In Card Layouts+1
Itthidej Aramsri
·
Published
2026-03-19
·
Updated
2026-03-23
·
CVE-2026-4120
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Info Cards – Add Text and Media in Card Layouts plugin for WordPress versions up to and including 2.0.7
Description
The Info Cards plugin for WordPress is susceptible to Stored Cross-Site Scripting through the
btnUrl parameter within the Info Cards block. Insufficient input validation on URL schemes, specifically the lack of filtering for the javascript: protocol, allows attackers to inject malicious code. The render.php file passes attributes as JSON to the frontend, and the client-side view.js renders the btnUrl value directly as an href attribute without protocol sanitization. Authenticated attackers with Contributor-level access or higher can exploit this to execute arbitrary web scripts when a user clicks the rendered button link.Recommendations
Versions prior to and including 2.0.7 should be updated to a newer, fixed version when available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Infocard
Info Cards – Add Text/Media In Card Layouts