What is CVE-2026-14592?
The WP Real IP-based Access Control plugin (up to 1.3.1) lacks nonce and capability checks when storing options, allowing unauthenticated users to inject arbitrary JavaScript via CSRF. This stored XSS executes in the context of any user visiting the settings page, leading to potential compromise of WordPress sessions.
Azərbaycanca: Bu boşluq WP Real IP-based Access Control plagininin (1.3.1 versiyasına qədər) autentifikasiya olunmamış istifadəçilərə CSRF hücumu vasitəsilə parametr saxlamağa imkan verir ki, bu da saxlanılan JavaScript kodunun icrasına səbəb olur. Plaginin həssas funksiyalarında "nonce" yoxlaması və funksionallıq icazəsi (capability check) olmadığı üçün, istifadəçi müdaxilə olunmuş səhifəni ziyarət etdikdə ixtiyari JavaScript kodu icra oluna bilər.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What vulnerability does the "WP Real IP-based Access Control" plugin have?
The plugin up to version 1.3.1 lacks nonce and capability checks when storing options, allowing unauthenticated users to inject arbitrary JavaScript via CSRF.
What type of attack can this vulnerability lead to?
The vulnerability leads to stored XSS, where the injected arbitrary JavaScript executes in the context of any user visiting the affected settings page.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.