CVE-2026-81404
—Reflected XSS in IPGP Visitors Origin WordPress Plugin
The IPGP Visitors Origin WordPress plugin before version 1.6 does not sanitise or escape user-supplied input before reflecting it back in the HTTP response, creating a Reflected Cross-Site Scripting flaw (CWE-79). An unauthenticated attacker can trigger it by getting a site user to submit a crafted request, for example by convincing them to open a maliciously crafted link whose payload parameters are processed and echoed by the plugin. Successful exploitation executes attacker-controlled JavaScript in the victim's browser in the context of the affected site (CVSS 7.1, user interaction required, changed scope, low confidentiality and integrity impact), potentially enabling actions such as performing actions on the user's behalf. Any WordPress installation running an affected version of the plugin is exposed, though the installed base is not quantified in the available data. No exploitation is currently known: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 0.2% probability of exploitation within 30 days.
What to do: Update the IPGP Visitors Origin plugin to version 1.6 or later; if immediate updating is not possible, deactivate the plugin, since the flaw is exploitable by unauthenticated attackers. Because the attack is reflected and user-interaction dependent, caution administrators and users against clicking untrusted links that point to the site. No in-the-wild exploitation is known, so patching within a normal maintenance cycle is reasonable.
| IPGP Visitors Origin (WordPress plugin) | all versions before 1.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who are tricked into submitting a crafted request.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.