CVE-2026-10827
Last modified
CVE-2026-10827 is a low-severity vulnerability rated 3.5/10 on the CVSS scale. The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into the pages that render the affected block. The injected styles are served to anonymous visitors of those pages and can force external resource loads, deface/redress the page, or exfiltrate data via CSS attribute selectors. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into the pages that render the affected block. The injected styles are served to anonymous visitors of those pages and can force external resource loads, deface/redress the page, or exfiltrate data via CSS attribute selectors. JavaScript execution is not possible at this role (the script-tag breakout is removed by KSES), so the impact is limited to CSS injection.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Spectra Legacy | < 2.20.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-10827?
How severe is CVE-2026-10827?
How do I fix CVE-2026-10827?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1082The TITLE ANIMATOR plugin for WordPress is vulnerable to Cro…4.3
- CVE-2026-10820The Paid Membership Plugin, Ecommerce, User Registration For…8.1
- CVE-2026-10822If BIND encounters a particular invalid data structure in a …6.5
- CVE-2026-10823The YMC Filter WordPress plugin before 3.11.3 does not prope…7.5
- CVE-2026-10824The Masteriyo LMS WordPress plugin before 2.2.1 does not pe…6.5
- CVE-2026-10825A denial-of-service vulnerability exists in the WebSocket AP…7.1
- CVE-2026-10828A format string vulnerability has been found in the "alias" …6.9
- CVE-2026-10829A stack-based buffer overflow vulnerability has been found i…8.6
- CVE-2026-1083The Appointment Hour Booking – Booking Calendar plugin for W…4.4
- CVE-2026-10830The AllCoach WordPress plugin before 1.0.2 does not verify …8.8
- CVE-2026-10831A denial-of-service vulnerability exists in NPort devices be…6.9
- CVE-2026-10833The Gutenberg Essential Blocks – Page Builder for Gutenberg …6.4
Are you affected by CVE-2026-10827?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
