Stored XSS in Presto Player WordPress Plugin
The Presto Player WordPress plugin is vulnerable to Stored Cross-Site Scripting via the presto-player tag, allowing unauthenticated attackers to execute arbitrary web scripts.
CVE search metadata
CVE search record: CVE-2026-96682. Severity: high. CVSS: 7.2. KEV: no. Product: Presto Player (<= 4.5.1). Brief: Stored XSS in Presto Player WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-presto-player-xss/
The Presto Player plugin for WordPress (versions up to and including 4.5.1) contains a Stored Cross-Site Scripting (XSS) vulnerability. The flaw stems from insufficient input sanitization and output escaping when processing content within the <presto-player> tag. An unauthenticated attacker can inject arbitrary malicious scripts into comment fields. While the initial injection may require comment approval, WordPress default settings often auto-approve subsequent comments from the same author, providing an attacker with a mechanism to persist and execute payloads without further administrative intervention. Impact includes unauthorized script execution within the context of a victim's session, potentially leading to session hijacking, defacement, or redirection to malicious sites.
Attack Chain
- Attacker identifies a WordPress site with Presto Player plugin version 4.5.1 or earlier installed.
- Attacker crafts a malicious comment containing a crafted <presto-player> tag with embedded JavaScript.
- Attacker submits the comment via the public comment form.
- Attacker leverages the site's default auto-approval configuration or waits for manual administrator approval of the comment.
- The malicious script is stored in the WordPress database linked to the comment content.
- Victim visits the page where the comment is rendered.
- The browser renders the <presto-player> tag, triggering the execution of the injected script in the context of the victim's session.
- Attacker achieves malicious script execution (e.g., session token theft).
Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary scripts in the browsers of site visitors, including administrators. This can lead to account takeover, unauthorized actions performed on behalf of authenticated users, and theft of sensitive session information. The vulnerability affects all users running vulnerable versions of the Presto Player plugin.
Recommendation
Update the Presto Player plugin to the latest available version beyond 4.5.1 to remediate CVE-2026-96682. Implement a Web Application Firewall (WAF) to detect and block malicious script injection attempts targeting the <presto-player> tag in comment inputs. Review WordPress comment moderation settings to require manual approval for all new user comments to mitigate auto-approval exploitation vectors.
Immediate actions
Upgrade Presto Player plugin to version 4.5.2 or later.
Mitigations
Enable manual comment moderation for all users in WordPress settings.
CVE-2026-96682