Skip to content
Threat Feed
high advisory

Stored XSS in DoFollow Case by Case WordPress Plugin

The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization, allowing unauthenticated attackers to execute arbitrary scripts in the browsers of site visitors.

CVE search metadata

CVE search record: CVE-2026-95817. Severity: high. CVSS: 7.2. KEV: no. Product: DoFollow Case by Case (<= 3.6.0). Brief: Stored XSS in DoFollow Case by Case WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-dofollow-xss/

The DoFollow Case by Case plugin for WordPress (all versions up to and including 3.6.0) contains a vulnerability that permits Stored Cross-Site Scripting (XSS). This flaw stems from the plugin's failure to properly sanitize and escape content submitted via comment fields. Because the input is not validated, an unauthenticated attacker can embed malicious JavaScript payloads within a comment submission.

While standard WordPress comment moderation settings may delay the delivery of the exploit, once an administrator approves a comment containing a payload, the script is rendered on the post page. Subsequently, the script executes within the context of any user's browser who views the affected post, including site administrators. This vulnerability poses a significant risk to the integrity of the WordPress site by enabling session hijacking, account takeover, or unauthorized administrative actions. Defenders should treat this as a high-priority risk if the plugin cannot be immediately updated or removed.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browsers of site visitors, including high-privileged administrators. This can lead to the theft of session cookies, the creation of rogue administrator accounts, or unauthorized content modification, effectively compromising the WordPress site and its user base.

Recommendation

  • Update the DoFollow Case by Case plugin to a patched version beyond 3.6.0 immediately.
  • Disable the comment feature on public-facing posts until the patch is verified and applied.
  • Monitor web server logs for suspicious HTTP POST requests directed at comment submission endpoints (/wp-comments-post.php) containing script tags or common XSS vectors.

Immediate actions

Update DoFollow Case by Case plugin to version > 3.6.0

IT Operations 24h

Mitigations

Disable comment functionality for affected WordPress posts

immediate IT Operations

CVE-2026-95817