What is CVE-2026-17010?
This vulnerability is in the "Saitama Addon Pack" WordPress plugin up to version 1.0.8. It fails to sanitize post metadata values, allowing contributor-level and above users to inject stored XSS payloads that execute in the browser of higher-privileged users. Updating the plugin to a secure version is required to mitigate this issue.
Azərbaycanca: Bu boşluq "Saitama Addon Pack" WordPress plaginində (1.0.8 versiyasına qədər) aşkarlanıb. Plagin post metadata dəyərlərini düzgün sanitizasiya etmədiyi üçün contributor və daha yuxarı səlahiyyətli istifadəçilər Stored XSS hücumu həyata keçirə bilər. Yüksək səlahiyyətli istifadəçilərin brauzerində icra olunan bu hücumdan qorunmaq üçün plagini təhlükəsiz versiyaya yeniləmək tələb olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Up to which version is the Saitama Addon Pack plugin affected by CVE-2026-17010?
The vulnerability affects all versions of the plugin up to 1.0.8.
What is the minimum user privilege required to exploit CVE-2026-17010?
A minimum of contributor-level privileges is required to carry out this Stored XSS attack.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.