PT-2026-38904 · WordPress · Sky Addons

Athiwat Tiprasaharn

·

Published

2026-05-08

·

Updated

2026-05-09

·

CVE-2026-7475

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sky Addons versions prior to 3.3.3
Description The Sky Addons plugin for WordPress allows authenticated attackers with Author-level access or higher to inject arbitrary web scripts. This occurs because the sky-custom-scripts custom post type is registered with capability type => 'post' and show in rest => true, while the sky script content meta field lacks sufficient input sanitization and output escaping during frontend rendering. These scripts are executed on every frontend page for all site visitors via the REST API.
Recommendations Update the plugin to a version later than 3.3.2. As a temporary workaround, restrict access to the REST API or limit user permissions to prevent Author-level users from modifying the sky script content meta field.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7475

Affected Products

Sky Addons