PT-2026-38903 · WordPress · Nmr Strava Activities

Djaidja Moundjid

·

Published

2026-05-08

·

Updated

2026-05-09

·

CVE-2026-5341

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions NMR Strava activities plugin for WordPress versions prior to 1.0.15
Description Insufficient input sanitization and output escaping on user supplied attributes in the strava nmr connect shortcode allow authenticated attackers with contributor-level access and above to inject arbitrary web scripts. These scripts execute whenever a user accesses a page containing the injected content. This is a Stored Cross-Site Scripting issue, where malicious scripts are permanently stored on the target server.
Recommendations Update the plugin to a version later than 1.0.14. As a temporary workaround, restrict the use of the strava nmr connect shortcode to trusted users with higher privilege levels.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5341

Affected Products

Nmr Strava Activities