Skip to main content
Vulnerability Database/CVE-2026-92712

CVE-2026-92712: ReactPress WordPress Plugin XSS Vulnerability

CVE-2026-92712 is a stored cross-site scripting flaw in the ReactPress WordPress plugin that lets authenticated attackers inject malicious scripts. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-92712 Overview

CVE-2026-92712 is a Stored Cross-Site Scripting (XSS) vulnerability in the ReactPress – Create React App for WordPress plugin. The flaw affects all versions up to and including 3.4.0. Authenticated attackers with subscriber-level access or above can inject arbitrary JavaScript into WordPress pages. The vulnerability stems from the permalink parameter being passed only through sanitize_url(), which does not block attacker-controlled remote URLs. The plugin then writes the fetched response body verbatim to disk via file_put_contents(), persisting script tags and event-handler attributes into served pages. The issue is tracked under [CWE-79].

Critical Impact

Subscriber-level accounts can plant persistent JavaScript that executes in the browser of every visitor to the injected page, enabling session theft, account takeover, and administrative privilege escalation.

Affected Products

  • ReactPress – Create React App for WordPress plugin
  • All versions up to and including 3.4.0
  • WordPress sites permitting subscriber-level registration with the plugin installed

Discovery Timeline

  • 2026-09-30 - CVE-2026-92712 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-92712

Vulnerability Analysis

The ReactPress plugin exposes functionality that lets authenticated users register a permalink associated with a React application. During processing, the plugin fetches content from a URL tied to that permalink and writes the response body directly to a file on the WordPress filesystem. That file is then served as part of the rendered page. Because the plugin fails to sanitize the response body or escape output before serving it, any HTML — including <script> tags and event-handler attributes such as onerror or onload — is executed in the victim's browser session.

Root Cause

The root cause is insufficient input sanitization combined with missing output escaping. The permalink parameter passes through sanitize_url(), which validates URL structure but does not restrict the destination host or filter the retrieved payload. Downstream, file_put_contents() writes the raw response to disk without HTML encoding. See the plugin sources in Admin.php L220, Controller.php L201, Controller.php L339, and Core.php L153.

Attack Vector

An attacker authenticates to the WordPress site with at least subscriber privileges. The attacker submits a permalink value pointing at a remote server they control. The plugin fetches that URL and writes the response — containing malicious HTML and JavaScript — to a file served by the WordPress site. When any user, including administrators, loads the resulting page, the injected script executes in their browser context. See the Wordfence Vulnerability Report for additional detail.

Detection Methods for CVE-2026-92712

Indicators of Compromise

  • Unexpected files created by the ReactPress plugin containing <script> tags, inline event handlers such as onerror= or onload=, or references to external JavaScript resources.
  • WordPress access logs showing subscriber-level accounts invoking ReactPress admin endpoints that accept a permalink parameter.
  • Outbound HTTP requests from the WordPress server to unfamiliar external hosts triggered by plugin-initiated fetches.
  • New or modified React app entries in the plugin's storage directory that were not created by trusted administrators.

Detection Strategies

  • Scan the ReactPress plugin's on-disk asset directories for HTML or JavaScript payloads not produced by legitimate React builds.
  • Correlate WordPress user_meta and audit logs to identify low-privilege accounts creating or updating ReactPress applications.
  • Review web server logs for anomalous responses served from paths managed by ReactPress that contain script content.

Monitoring Recommendations

  • Enable and centralize WordPress audit logging to capture plugin configuration changes performed by non-admin roles.
  • Monitor egress traffic from the web tier for requests to unknown domains initiated by PHP processes.
  • Alert on file-write events under the ReactPress plugin path that include HTML or JavaScript signatures.

How to Mitigate CVE-2026-92712

Immediate Actions Required

  • Upgrade the ReactPress – Create React App for WordPress plugin to a version above 3.4.0 once the vendor publishes a fix.
  • Audit existing ReactPress applications and remove any entries created by untrusted or subscriber-level accounts.
  • Restrict new user registration or set the default role to a level that cannot access ReactPress functionality where feasible.
  • Rotate administrator session cookies and credentials if any subscriber-authored React apps are found on the site.

Patch Information

At the time of publication, no fixed version is listed in the NVD entry. All versions up to and including 3.4.0 are affected. Consult the Wordfence Vulnerability Report and the ReactPress plugin repository for updates and the eventual patched release.

Workarounds

  • Deactivate and remove the ReactPress plugin until a patched version is available if it is not business-critical.
  • Apply a Web Application Firewall (WAF) rule that blocks POST requests to ReactPress admin endpoints from non-administrator sessions.
  • Restrict outbound HTTP requests from the WordPress server so that plugin-initiated fetches cannot reach arbitrary attacker-controlled hosts.
  • Enforce a strict Content Security Policy (CSP) that disallows inline scripts and unauthorized external script sources.
bash
# Example: temporarily disable the ReactPress plugin via WP-CLI
wp plugin deactivate reactpress
wp plugin delete reactpress

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.