PT-2026-38903 · WordPress · Nmr Strava Activities
Djaidja Moundjid
·
Published
2026-05-08
·
Updated
2026-05-09
·
CVE-2026-5341
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
NMR Strava activities plugin for WordPress versions prior to 1.0.15
Description
Insufficient input sanitization and output escaping on user supplied attributes in the
strava nmr connect shortcode allow authenticated attackers with contributor-level access and above to inject arbitrary web scripts. These scripts execute whenever a user accesses a page containing the injected content. This is a Stored Cross-Site Scripting issue, where malicious scripts are permanently stored on the target server.Recommendations
Update the plugin to a version later than 1.0.14.
As a temporary workaround, restrict the use of the
strava nmr connect shortcode to trusted users with higher privilege levels.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nmr Strava Activities