CVE-2026-85129
—1Unauthenticated Stored XSS and Settings Wipe in Hoo Companion WordPress Plugin 1.0.2
The Hoo Companion WordPress plugin, version 1.0.2, performs no authorisation, validation, or sanitisation on one of its import features, which writes submitted data directly into the active theme's settings. An unauthenticated attacker can send a crafted request to this endpoint to inject arbitrary JavaScript that executes in the browsers of any site visitor, including administrators, enabling session hijacking and full site takeover. The same malicious request overwrites and destroys the site's existing theme settings, breaking the site's appearance and configuration. Any WordPress site running the plugin alongside its companion theme is affected. There is no known public proof of concept and no evidence of in-the-wild exploitation at this time.
What to do: Remove or deactivate the Hoo Companion plugin until a patched version newer than 1.0.2 is available, and check the plugin's repository for security advisories. Inspect the active theme's settings for unexpected or foreign scripts and restore them from a known-good backup, since exploitation wipes legitimate settings. Review administrator accounts and sessions for compromise, and use a WAF rule to block unauthenticated requests to the plugin's import endpoint if it must remain enabled.
| Hoo Companion (WordPress plugin vendor) Hoo Companion WordPress plugin | 1.0.2 and prior |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web scripts which will execute for anyone viewing the site, including administrators. The same request destroys the site's existing theme settings.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.