CVE-2026-1866: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-1866 is a Stored Cross-Site Scripting (XSS) vulnerability in the Name Directory plugin for WordPress, affecting all versions up to and including 1.32.0. The flaw allows unauthenticated attackers to inject arbitrary web scripts via the name_directory_name and name_directory_description parameters in the plugin's public submission form. It was published on February 10, 2026, with a CVSS v3.1 base score of 7.2 (High) (Red Hat CVE, Wordfence).

Technical details

The root cause is improper input sanitization classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). The plugin's sanitization routine calls html_entity_decode() before wp_kses() to strip disallowed HTML, and then calls html_entity_decode() again on output — a double-decoding flaw that allows double HTML-entity-encoded payloads to bypass the sanitization filter entirely. An unauthenticated attacker submits a malicious entry via the public name/description submission form; the injected script executes in the browser of any user who views the approved or auto-published page (Red Hat CVE, Infinitsec).

Impact

Successful exploitation results in persistent script execution in the context of any user — including administrators — who visits an affected page, enabling session hijacking, credential theft, defacement, or further malicious redirects. Because the scope is changed (S:C in CVSS), the injected script can affect resources beyond the plugin itself, such as the broader WordPress site. Sites with auto-publish enabled face immediate risk without any administrator interaction, while others require an administrator to approve the malicious submission (Red Hat CVE, Wordfence).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.123%, indicating a low probability of near-term exploitation. The vulnerability is detectable by Qualys (detection ID 530938) and has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Sites with auto-publish enabled are at elevated risk as no administrator interaction is required (Red Hat CVE, Qualys).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Name Directory plugin (version ≤ 1.32.0) by searching for the plugin's public submission form or using tools like WPScan.
  2. Craft payload: Prepare a double HTML-entity-encoded XSS payload (e.g., <script>alert(1)</script>) that will survive the first html_entity_decode() + wp_kses() pass and decode to executable JavaScript on the second html_entity_decode() call at output.
  3. Submit malicious entry: Submit the crafted payload via the plugin's public name/description submission form using the name_directory_name or name_directory_description parameters — no authentication is required.
  4. Wait for approval or rely on auto-publish: If auto-publish is enabled, the entry is immediately live. Otherwise, use social engineering or repeated submissions to get an administrator to approve the entry.
  5. Script executes: When any user (including an administrator) visits the page containing the injected entry, the decoded script executes in their browser, enabling session token theft, credential harvesting, or further attacks (Infinitsec, Red Hat CVE).

Indicators of compromise

  • Network: Unusual POST requests to the Name Directory public submission endpoint containing double HTML-entity-encoded strings (e.g., <script>) in name_directory_name or name_directory_description parameters.
  • Logs: WordPress access logs showing repeated submissions to the Name Directory form from the same or rotating IP addresses, particularly with encoded script tags in parameter values.
  • File System / Database: Name Directory entries in the WordPress database (wp_posts or plugin-specific tables) containing HTML-entity-encoded script tags or JavaScript event handlers.
  • Browser/User Reports: Unexpected JavaScript alerts, redirects, or unauthorized actions reported by users visiting Name Directory pages on the affected site.

Mitigation and workarounds

Update the Name Directory plugin to version 1.32.1 or later, which corrects the double HTML-entity decoding flaw in the sanitization routine. As an interim workaround, disable the public submission form or disable the auto-publish feature to require administrator review of all submissions, reducing the attack surface. Site administrators should also audit existing Name Directory entries for suspicious or encoded content and remove any malicious submissions (Wordfence, Red Hat CVE).

Community reactions

Wordfence included this vulnerability in their weekly WordPress vulnerability report for February 9–15, 2026, highlighting the unauthenticated nature of the attack and the risk posed by auto-publish configurations (Wordfence). RedPacket Security also flagged the CVE via social media shortly after disclosure (RedPacket Security). Overall community reaction has been moderate, consistent with a medium-severity WordPress plugin XSS with a straightforward patch available.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management