WordPress Plugin Netroics Blog Posts Grid Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Plugin Netroics Blog Posts Grid, version 1.0. This vulnerability allows authenticated editors to inject malicious scripts by exploiting the post_title parameter, which is not properly sanitized. The injected scripts can execute in the browsers of other users who view the draft post, potentially leading to cookie theft and session hijacking.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the post.

Reproduction

To reproduce this vulnerability, log in as an editor and create a new testimonial. Inject a script payload into the title field, which corresponds to the post_title parameter. After saving the draft, the injected script will execute when the post is previewed by another editor or admin.

Added: May 10, 2026, 1:27 PM
Updated: May 10, 2026, 1:27 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.3
remediation
0.0
relevance
7.9
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.