WordPress Plugin Vulnerabilities

Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta

Description

The plugin does not sanitise and escape certain post metadata values before outputting them, allowing users with contributor-level access and above to inject stored Cross-Site Scripting payloads that execute in the browser of a higher-privileged user who reviews the content.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
testoun
Submitter
testoun
Verified
Yes

Timeline

Publicly Published
2026-08-05 (about 4 days ago)
Added
2026-07-29 (about 11 days ago)
Last Updated
2026-07-29 (about 11 days ago)

Other