What is CVE-2026-17162?
CVE-2026-17162 is a Stored Cross-Site Scripting vulnerability in the WowStore plugin for WordPress. The issue arises from insufficient input sanitization and output escaping in the 'currentPostId' block attribute, affecting all plugin versions up to 4.4.24. Authenticated users can inject malicious scripts, so updating the plugin to the latest patched version is strongly advised.
Azərbaycanca: CVE-2026-17162, WordPress üçün WowStore plaginində saxlanılan Cross-Site Scripting zəifliyidir. Bu zəiflik 'currentPostId' blok atributunda kifayət qədər input sanitization və output escaping olmaması səbəbindən baş verir və plaginin 4.4.24 daxil olmaqla bütün versiyalarına təsir edir. Autentifikasiya olunmuş istifadəçilər bu boşluq vasitəsilə zərərli skriptlər yerləşdirə bilər, buna görə istifadəçilərə plaginin ən son təhlükəsizlik yeniləməsinə keçmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Does exploiting CVE-2026-17162 in the WowStore plugin require authentication?
Yes, CVE-2026-17162 is a Stored Cross-Site Scripting vulnerability that can be exploited by authenticated users.
Which versions of the WowStore plugin are affected by CVE-2026-17162?
This vulnerability affects all versions of the WowStore plugin up to and including 4.4.24.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.