WordPress Plugin Vulnerabilities

Text Styler <= 1.1.1 - Contributor+ Stored XSS

Description

The plugin does not sanitise and escape user-supplied styling values before outputting them within a front-end style block, and does not verify that a user may edit the target post, allowing users with contributor-level access or above to store JavaScript that executes in the browser of anyone viewing the affected post, including administrators.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Pablo González Pérez, Francisco José Ramírez Vicente, and Iñigo Sánchez Enciso
Submitter
Francisco José Ramírez Vicente
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-19 (about 2 days ago)
Added
2026-09-12 (about 9 days ago)
Last Updated
2026-09-12 (about 9 days ago)

Other