
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2687 is a Stored Cross-Site Scripting (XSS) vulnerability in the Reading progressbar WordPress plugin affecting versions before 1.3.1. The flaw allows high-privilege users (admin-level) to inject and store malicious scripts via unsanitized plugin settings, even when the unfiltered_html capability is disabled — a scenario common in WordPress multisite environments. It was publicly disclosed on February 19, 2026, and assigned a CVSS v3.1 base score of 4.3 (Low/Medium) by Feedly, with WPScan reporting a CVSS of 3.5 (Low) (WPScan, Feedly).
The root cause is improper neutralization of user-supplied input in plugin settings fields (CWE-79). Specifically, the plugin fails to sanitize or escape values stored in the "Progressbar height (pixels)" and "Target fixed HTML element class/id to stick the bar on it's bottom" settings fields before rendering them in the browser. An attacker with admin privileges can inject a crafted payload such as ' style='animation-name:rotation' onanimationstart='alert(/XSS/)//' into these fields; when the page is loaded by any user, the stored script executes in their browser context. The vulnerability bypasses the unfiltered_html capability restriction, making it particularly relevant in WordPress multisite setups where that capability is typically restricted (WPScan).
Successful exploitation allows a malicious or compromised administrator to persistently inject JavaScript that executes in the browsers of other users visiting affected pages. In a WordPress multisite environment, this could enable session hijacking, credential theft, defacement, or redirection of users to malicious sites. While the attacker must already hold admin-level access, the bypass of unfiltered_html restrictions means the attack surface extends to environments where such controls are expected to provide a security boundary (WPScan, Feedly).
No public exploit kit integration or in-the-wild exploitation has been reported for this vulnerability. A proof-of-concept payload is publicly documented in the WPScan advisory. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated admin-level access, significantly limiting the attack surface (WPScan, Feedly).
' style='animation-name:rotation' onanimationstart='alert(/XSS/)//'onanimationstart, onerror, onload) or <script> tags within the reading-progress-bar plugin option values in the wp_options table.Update the Reading progressbar WordPress plugin to version 1.3.1 or later, which includes proper sanitization and escaping of the affected settings fields. No configuration-based workaround is available; upgrading is the only effective remediation. Site administrators should also audit plugin settings for any previously stored malicious payloads and review admin account activity for unauthorized changes (WPScan).
The vulnerability was discovered and reported by researcher Krugov Artyom via CleanTalk's security research team and verified by WPScan. Wordfence included it in their weekly WordPress vulnerability report for the week of March 9–15, 2026. Coverage has been limited to standard vulnerability aggregation platforms and security feeds, with no significant broader media or community discussion noted (WPScan, Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."