ZeroHour

CVE-2026-81765

Unauthenticated Cross-Site Scripting (XSS) in WordPress Tailored Tools plugin

CVSS 3.1
7.1 high
EPSS
<1%p4
Published
()
Modified
AI analysis

CVE-2026-81765 is a cross-site scripting flaw (CWE-79) in the Tailored Tools plugin for WordPress, affecting all versions up to and including 3.0.2, that can be triggered without authentication. An attacker can inject unsanitized script content that is then executed in the browser of a user who views the affected page, with the scope-changed CVSS vector indicating the impact can extend beyond the vulnerable component. Successful exploitation can allow the attacker to run arbitrary JavaScript in a victim's session — for example stealing cookies or performing actions as an administrator if a privileged user is targeted — though the CVSS scoring limits confidentiality/integrity impact to low and requires user interaction. Any WordPress site running the Tailored Tools plugin at version 3.0.2 or older is affected. Exploitation has not been observed: there is no known public proof-of-concept, the EPSS probability is only about 0.1% over 30 days, and the flaw is not in CISA's Known Exploited Vulnerabilities catalog.

What to do: Sites running Tailored Tools should update to the newest release as soon as a version newer than 3.0.2 is published; until a fix is available, deactivate the plugin or restrict access to it, and consider a WAF rule to block reflected script injection. Administrators should check for unusual injected scripts or unexpected admin activity, though with no public PoC and low EPSS there is currently no indication of active exploitation.

Affected
Tailored Tools WordPress plugin<= 3.0.2
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.