PT-2026-42062 · Cvmh · Sticky
Djaidja Moundjid
·
Published
2026-05-20
·
Updated
2026-05-20
·
CVE-2026-6397
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
cvmh-sticky shortcode readmoretext attribute in versions up to and including 2.5.6. This is due to insufficient input sanitization and output escaping in the cvmh sticky front render() function — the readmoretext attribute value is passed through apply filters() and directly concatenated into the HTML output without any escaping function such as esc html(). This makes it possible for authenticated attackers with Contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses a page containing the injected shortcode.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sticky