CVE-2026-3551
Last modified
CVE-2026-3551 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. The Custom New User Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's admin settings in all versions up to, and including, 1.2.0. This is due to insufficient input sanitization and output escaping on multiple settings fields including 'User Mail Subject', 'User From Name', 'User From Email', 'Admin Mail Subject', 'Admin From Name', and 'Admin From Email'. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
The Custom New User Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's admin settings in all versions up to, and including, 1.2.0. This is due to insufficient input sanitization and output escaping on multiple settings fields including 'User Mail Subject', 'User From Name', 'User From Email', 'Admin Mail Subject', 'Admin From Name', and 'Admin From Email'. The settings are registered via register_setting() without sanitize callbacks, and the values retrieved via get_option() are echoed directly into HTML input value attributes without esc_attr(). This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in the plugin settings page that will execute whenever a user accesses that page. This could be used in multi-site installations where administrators of subsites could target super administrators.
Metrics
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-3551?
How severe is CVE-2026-3551?
How do I fix CVE-2026-3551?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-35503A vulnerability in SenseLive X3050’s web management interfac…9.8
- CVE-2026-35504PowerSYSTEM Center email notification service is affected by…5.5
- CVE-2026-35505An unauthenticated remote attacker can repeatedly send craft…8.7
- CVE-2026-35506ELECOM wireless LAN access point devices contain an OS comma…8.6
- CVE-2026-35507Shynet before 0.14.0 allows Host header injection in the pas…6.5
- CVE-2026-35508Shynet before 0.14.0 allows XSS in urldisplay and iconify te…6.1
- CVE-2026-35512xrdp is an open source RDP server. Versions through 0.10.5 h…8.8
- CVE-2026-35514Chartbrew is an open-source web application that can connect…6.5
- CVE-2026-35515Nest is a framework for building scalable Node.js server-sid…6.1
- CVE-2026-35516LinkAce is a self-hosted archive to collect website links. P…5
- CVE-2026-35517FTLDNS (pihole-FTL) provides an interactive API and also gen…8.8
- CVE-2026-35518FTLDNS (pihole-FTL) provides an interactive API and also gen…8.8
Are you affected by CVE-2026-3551?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
