CVE-2026-2502

The xmlrpc attacks blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0, via the 'X-Forwarded-For' HTTP header. This is due to the plugin trusting and logging attacker-controlled IP header data and rendering debug log entries without output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the debug log page.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) El plugin xmlrpc attacks blocker para WordPress es vulnerable a cross-site scripting almacenado en versiones hasta la 1.0, inclusive, a través del encabezado HTTP 'X-Forwarded-For'. Esto se debe a que el plugin confía y registra datos de encabezado IP controlados por el atacante y renderiza entradas del registro de depuración sin escape de salida. Esto hace posible que atacantes no autenticados inyecten scripts web arbitrarios que se ejecutan cuando un administrador ve la página del registro de depuración.

19 Feb 2026, 07:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 07:17

Updated : 2026-06-17 10:31


NVD link : CVE-2026-2502

Mitre link : CVE-2026-2502

CVE.ORG link : CVE-2026-2502


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')