PT-2026-42062 · Cvmh · Sticky

Djaidja Moundjid

·

Published

2026-05-20

·

Updated

2026-05-20

·

CVE-2026-6397

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the cvmh-sticky shortcode readmoretext attribute in versions up to and including 2.5.6. This is due to insufficient input sanitization and output escaping in the cvmh sticky front render() function — the readmoretext attribute value is passed through apply filters() and directly concatenated into the HTML output without any escaping function such as esc html(). This makes it possible for authenticated attackers with Contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses a page containing the injected shortcode.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-6397

Affected Products

Sticky