PT-2026-6019 · WordPress · Extended Random Number Generator

0X34Rth

+1

·

Published

2026-02-04

·

Updated

2026-02-04

·

CVE-2026-0681

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Extended Random Number Generator versions prior to 1.2
Description The Extended Random Number Generator plugin for WordPress is susceptible to Stored Cross-Site Scripting through the plugin settings. Insufficient input sanitization and output escaping allow authenticated attackers with administrator-level access to inject arbitrary web scripts into pages. These scripts will execute when a user accesses the injected page. This issue specifically impacts multi-site installations and those where unfiltered html has been disabled.
Recommendations Update Extended Random Number Generator to version 1.2 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-0681

Affected Products

Extended Random Number Generator