Stored XSS Vulnerability in Extendify WordPress Plugin
The Extendify plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) via the 'styles.blocks' parameter, allowing arbitrary script injection.
CVE search metadata
CVE search record: CVE-2026-85679. Severity: high. CVSS: 7.2. KEV: no. Product: Extendify (<= 3.1.6). Brief: Stored XSS Vulnerability in Extendify WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-extendify-xss/
The Extendify plugin for WordPress (versions 3.1.6 and earlier) contains a critical stored Cross-Site Scripting (XSS) vulnerability stemming from insufficient input sanitization and output escaping within the 'styles.blocks' block type key. The vulnerability is triggered because the registerIncoming() function is hooked to rest_request_before_callbacks. This causes the vulnerable code path to execute during REST API requests before WordPress performs the necessary permission_callback checks. Consequently, unauthenticated attackers can successfully send malicious POST, PUT, or PATCH requests to the /wp/v2/global-styles route to inject arbitrary JavaScript. When a user subsequently views the affected page, the injected scripts execute in the context of the victim's session, potentially leading to administrative account takeover or session hijacking.
Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a WordPress user's session. This can lead to unauthorized actions performed as the user, administrative account compromise, or the redirection of site visitors to malicious external sites. The scope of impact is limited to users of WordPress sites running the vulnerable Extendify plugin version 3.1.6 or earlier.
Recommendation
- Immediately update the Extendify WordPress plugin to a version patched against CVE-2026-85679.
- Implement a Web Application Firewall (WAF) rule to inspect and block POST, PUT, or PATCH requests to the
/wp/v2/global-stylesendpoint that contain anomalous characters or script tags in thestyles.blocksparameter. - Review web server access logs for requests targeting
/wp/v2/global-styleswith unusual content types or payload structures.
Immediate actions
Patch Extendify plugin to the latest version beyond 3.1.6
Mitigations
Deploy WAF rule to filter POST/PUT/PATCH requests to /wp/v2/global-styles containing suspicious script tags
CVE-2026-85679
Detection coverage 1
Detects CVE-2026-85679 Exploitation - Unauthenticated XSS in Extendify
highDetects potential exploitation attempts targeting the Extendify plugin's REST API endpoint for global styles, where malicious payloads are injected via the styles.blocks parameter.
Detection queries are available on the platform. Get full rules →