
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24564 is a Basic XSS (Content Injection) vulnerability in the Textmetrics WordPress plugin (also known as webtexttool) developed by Israpil Textmetrics. The flaw allows authenticated attackers with subscriber-level privileges to inject malicious script-related HTML tags into web pages, enabling code injection. It affects all versions of the plugin up to and including 3.6.5, with version 3.6.6 containing the fix. The vulnerability was reported on December 22, 2025, and published by Patchstack on January 21–23, 2026. It carries a CVSS v3.1 base score of 4.3 (Medium), as assessed by Patchstack (Patchstack).
The vulnerability is classified as CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page — Basic XSS), where user-supplied input is not properly sanitized before being rendered in the browser. An authenticated attacker with at minimum subscriber-level access can inject malicious HTML or script-related tags into posts or pages managed by the Textmetrics plugin. The attack vector is network-based, requires low privileges, and no user interaction is needed per the updated Patchstack CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). No public proof-of-concept exploit code has been identified at this time (Patchstack).
Successful exploitation allows a malicious actor to inject arbitrary content — including phishing pages or script-related HTML — into posts and pages of the affected WordPress site, impacting the integrity of site content and potentially the confidentiality of site visitors. The confidentiality impact is limited (low), with no direct availability impact. While the vulnerability does not grant full system compromise, it can be leveraged in mass-exploit campaigns targeting WordPress sites regardless of their size or traffic, as noted by Patchstack (Patchstack).
There is no confirmed evidence of active in-the-wild exploitation or known weaponized exploit kits targeting CVE-2026-24564 at this time. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns against WordPress sites (Patchstack).
wp-content/plugins/webtexttool/readme.txt.<script>, <img onerror=...>) that are not properly sanitized.<script>, <img onerror=, or similar HTML injection patterns attributable to subscriber-level users.The vendor has released version 3.6.6 of the Textmetrics WordPress plugin, which resolves this vulnerability. Site administrators should update the plugin to version 3.6.6 or later immediately via the WordPress admin dashboard or by downloading the patched version from the WordPress plugin repository. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard. If an immediate update is not possible, restricting subscriber-level user registration or disabling the plugin temporarily are viable interim mitigations (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."