WordPress Plugin Vulnerabilities

Content Egg < 11.9.0 - Contributor+ Stored XSS via Import Queue

Description

The plugin does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary web scripts unfiltered under a privileged user's account, executing in the context of anyone who later views that content.

Proof of Concept

Affects Plugins

Fixed in 11.9.0

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
aymen benlamari
Submitter
aymen benlamari
Verified
Yes

Timeline

Publicly Published
2026-09-28 (about 2 days ago)
Added
2026-09-28 (about 1 day ago)
Last Updated
2026-09-28 (about 1 day ago)

Other