CVE-2026-81765
—Unauthenticated Cross-Site Scripting (XSS) in WordPress Tailored Tools plugin
CVE-2026-81765 is a cross-site scripting flaw (CWE-79) in the Tailored Tools plugin for WordPress, affecting all versions up to and including 3.0.2, that can be triggered without authentication. An attacker can inject unsanitized script content that is then executed in the browser of a user who views the affected page, with the scope-changed CVSS vector indicating the impact can extend beyond the vulnerable component. Successful exploitation can allow the attacker to run arbitrary JavaScript in a victim's session — for example stealing cookies or performing actions as an administrator if a privileged user is targeted — though the CVSS scoring limits confidentiality/integrity impact to low and requires user interaction. Any WordPress site running the Tailored Tools plugin at version 3.0.2 or older is affected. Exploitation has not been observed: there is no known public proof-of-concept, the EPSS probability is only about 0.1% over 30 days, and the flaw is not in CISA's Known Exploited Vulnerabilities catalog.
What to do: Sites running Tailored Tools should update to the newest release as soon as a version newer than 3.0.2 is published; until a fix is available, deactivate the plugin or restrict access to it, and consider a WAF rule to block reflected script injection. Administrators should check for unusual injected scripts or unexpected admin activity, though with no public PoC and low EPSS there is currently no indication of active exploitation.
| Tailored Tools WordPress plugin | <= 3.0.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.