Stored Cross-Site Scripting in CMB2 WordPress Plugin
The CMB2 plugin for WordPress (<= 2.13.0) is vulnerable to Stored XSS via the file_list field type, allowing unauthenticated attackers to inject malicious scripts into public-facing forms or user meta boxes.
CVE search metadata
CVE search record: CVE-2026-97336. Severity: high. CVSS: 7.2. KEV: no. Product: CMB2 (<= 2.13.0). Brief: Stored Cross-Site Scripting in CMB2 WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cmb2-xss/
The CMB2 plugin for WordPress, a popular developer toolkit, contains a Stored Cross-Site Scripting (XSS) vulnerability in the 'file_list' field type, tracked as CVE-2026-97336. The vulnerability stems from insufficient input sanitization and output escaping within the field's handling logic. Attackers can exploit this by injecting arbitrary web scripts into any publicly accessible front-end form or user meta box that leverages this specific CMB2 field type. Because CMB2 functions as a developer library rather than a standalone user-facing product, the actual exposure of this flaw is dependent on how third-party themes or plugins implement these fields. Successful exploitation allows for the execution of malicious scripts in the context of a victim's session, which may lead to unauthorized actions or credential theft. This issue affects all versions of the CMB2 plugin up to and including 2.13.0.
Impact
Successful exploitation of this vulnerability enables unauthenticated attackers to perform Stored XSS, allowing for the execution of arbitrary JavaScript in the browser of any user viewing the affected page. This can result in session hijacking, unauthorized modification of site content, or the redirection of users to malicious external domains. The scope of impact is contingent upon the prevalence of publicly accessible forms or meta boxes built with the CMB2 library across the target WordPress environment.
Recommendation
- Upgrade the CMB2 plugin to the latest version beyond 2.13.0 to include necessary sanitization and escaping patches.
- Review custom themes and plugins that utilize the CMB2 library to identify instances where 'file_list' fields are exposed in public-facing forms or front-end user meta boxes.
- Implement and enforce a strict Content Security Policy (CSP) to mitigate the impact of potential XSS vulnerabilities by restricting script execution sources.
Immediate actions
Inventory all WordPress sites using the CMB2 plugin and verify the currently installed version.
Mitigations
Upgrade CMB2 plugin to the latest version.
CVE-2026-97336