What is CVE-2026-13701?
CVE-2026-13701 is a Stored XSS vulnerability in the Advanced Excerpt WordPress plugin before version 4.5, caused by the lack of sanitization and escaping of one of its settings output on the front end. This allows administrators, including those without the 'unfiltered_html' capability on multisite networks, to execute malicious scripts. Updating the plugin to version 4.5 or later is required.
Azərbaycanca: CVE-2026-13701, Advanced Excerpt WordPress plagininin 4.5-dən əvvəlki versiyalarında bir parametrin sanitizə və escape edilməməsi səbəbindən Stored XSS zəifliyidir. Bu, administratorlara (xüsusilə multisite şəbəkələrində 'unfiltered_html' icazəsi olmayanlara) saytın ön hissəsində zərərli skript yerləşdirməyə imkan verir. Plagini ən azı 4.5 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Advanced Excerpt plugin are affected by CVE-2026-13701?
This Stored XSS vulnerability affects the Advanced Excerpt WordPress plugin in versions prior to 4.5.
Who can potentially place malicious scripts by exploiting CVE-2026-13701?
This vulnerability allows administrators, including those without the 'unfiltered_html' capability on multisite networks, to place malicious scripts on the front end of the site.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.