ZeroHour

CVE-2026-81771

large

Unauthenticated Cross-Site Scripting (XSS) in TrustedSite WordPress plugin <= 1.2.5

CVSS 3.1
7.1 high
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-81771 is an unauthenticated cross-site scripting (XSS) vulnerability in the TrustedSite plugin for WordPress, affecting all versions up to and including 1.2.5. Because the flaw requires no authentication and has low attack complexity, an attacker can deliver a crafted link or request, and the injected script executes when a user, such as a site administrator or visitor, interacts with it; the changed scope (S:C) in the CVSS vector indicates the script can run in other security zones, such as the admin area. Successful exploitation enables arbitrary JavaScript execution in the victim's browser, allowing actions such as session/cookie theft, performing actions on behalf of the victim, or injecting content into pages. Any WordPress site running TrustedSite 1.2.5 or earlier is affected. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS assigns only about a 0.2% probability of exploitation in the next 30 days, so no in-the-wild exploitation is currently known.

What to do: Update the TrustedSite plugin to the latest available version, i.e., any release newer than 1.2.5, and confirm the fixed version in the WordPress plugin directory or the Patchstack advisory. If immediate updating is not possible, temporarily deactivate the plugin; because exploitation requires user interaction, check access logs for suspicious crafted links and caution logged-in administrators against clicking unverified links pointing to affected sites.

Affected
TrustedSite WordPress plugin<= 1.2.5
Estimated exposure
largeTens of thousands of WordPress sites (estimated; the plugin has historically reported on the order of 100,000 active installs) — No install count was provided in the source data, so the estimate is based on the TrustedSite plugin's historically reported WordPress.org active-install base of roughly 100,000, tempered by the fact that not every install necessarily…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.