
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4335 is a Stored Cross-Site Scripting (XSS) vulnerability in the ShortPixel Image Optimizer plugin for WordPress, affecting all versions up to and including 6.4.3. The flaw allows authenticated attackers with Author-level access or above to inject arbitrary JavaScript that executes when a higher-privileged user (e.g., an administrator) opens the ShortPixel AI editor popup for a poisoned attachment. It was published on March 26, 2026, with Wordfence credited as the assigner. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Wordfence, Red Hat CVE).
The root cause is insufficient output escaping (CWE-79) in the getEditorPopup() function and its corresponding media-popup.php template. Specifically, AjaxController.php (line 435) retrieves an attachment's post_title from the database via get_post() and passes it directly to the view template (line 449), where it is rendered into an HTML <input> element's value attribute without applying WordPress's esc_attr() sanitization function (media-popup.php, line 139). Because WordPress permits Authors to set arbitrary attachment titles — including double-quote characters — via the REST API, a malicious author can craft a title that breaks out of the HTML attribute context and injects JavaScript event handlers. The injected script executes in the browser of any higher-privileged user who opens the ShortPixel AI editor popup (Background Removal or Image Upscale) for the poisoned attachment (Wordfence, WordPress Trac).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a higher-privileged user's browser session, such as an administrator. This can lead to session hijacking, credential theft, unauthorized administrative actions (e.g., creating rogue admin accounts, installing malicious plugins), and site defacement. While availability is not directly impacted, the confidentiality and integrity of the WordPress site and its data are at risk (Wordfence, Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-4335 as of the available data. The EPSS score is approximately 0.036%, indicating a low probability of exploitation in the near term. The vulnerability requires authenticated access at the Author level or above, and exploitation depends on a privileged user interacting with the poisoned attachment's editor popup, limiting opportunistic mass exploitation. It does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence).
PATCH /wp-json/wp/v2/media/<attachment_id>), update the attachment's post_title to a payload that breaks out of the HTML value attribute, such as: " onmouseover="alert(document.cookie) or a more sophisticated payload that exfiltrates session cookies to an attacker-controlled server.PATCH or POST requests to /wp-json/wp/v2/media/<id> from Author-level accounts with unusual or encoded title values containing HTML special characters (e.g., ", >, <, onerror, onmouseover).wp_posts where post_title contains JavaScript event handler strings (e.g., onmouseover=, onerror=, <script>) or encoded equivalents.Users should update the ShortPixel Image Optimizer plugin to a version beyond 6.4.3, which includes the fix applying proper esc_attr() escaping in media-popup.php. The patch was committed to the plugin repository (changeset 3490270) (WordPress Trac Changeset). As a temporary workaround where updating is not immediately possible, site administrators should restrict Author-level user accounts to trusted individuals only and monitor REST API activity for suspicious attachment title modifications. Enabling a Web Application Firewall (WAF) with XSS filtering rules can also help reduce risk (Wordfence).
Wordfence included CVE-2026-4335 in its weekly WordPress vulnerability report for the period of March 23–29, 2026, and Sucuri referenced it in its March 2026 vulnerability patch roundup (Wordfence Blog, Sucuri Blog). Community reaction has been limited given the medium severity rating and the requirement for authenticated access, with no significant controversy or widespread alarm noted in available sources.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."