ZeroHour

CVE-2026-85129

1

Unauthenticated Stored XSS and Settings Wipe in Hoo Companion WordPress Plugin 1.0.2

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

The Hoo Companion WordPress plugin, version 1.0.2, performs no authorisation, validation, or sanitisation on one of its import features, which writes submitted data directly into the active theme's settings. An unauthenticated attacker can send a crafted request to this endpoint to inject arbitrary JavaScript that executes in the browsers of any site visitor, including administrators, enabling session hijacking and full site takeover. The same malicious request overwrites and destroys the site's existing theme settings, breaking the site's appearance and configuration. Any WordPress site running the plugin alongside its companion theme is affected. There is no known public proof of concept and no evidence of in-the-wild exploitation at this time.

What to do: Remove or deactivate the Hoo Companion plugin until a patched version newer than 1.0.2 is available, and check the plugin's repository for security advisories. Inspect the active theme's settings for unexpected or foreign scripts and restore them from a known-good backup, since exploitation wipes legitimate settings. Review administrator accounts and sessions for compromise, and use a WAF rule to block unauthenticated requests to the plugin's import endpoint if it must remain enabled.

Affected
Hoo Companion (WordPress plugin vendor) Hoo Companion WordPress plugin1.0.2 and prior
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web scripts which will execute for anyone viewing the site, including administrators. The same request destroys the site's existing theme settings.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.