{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/extendify--3.1.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:extendify:extendify:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-85679"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Extendify (\u003c= 3.1.6)"],"_cs_severities":["high"],"_cs_tags":["xss","wordpress","web-application-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Extendify"],"content_html":"\u003cp\u003eThe Extendify plugin for WordPress (versions 3.1.6 and earlier) contains a critical stored Cross-Site Scripting (XSS) vulnerability stemming from insufficient input sanitization and output escaping within the 'styles.blocks' block type key. The vulnerability is triggered because the \u003ccode\u003eregisterIncoming()\u003c/code\u003e function is hooked to \u003ccode\u003erest_request_before_callbacks\u003c/code\u003e. This causes the vulnerable code path to execute during REST API requests before WordPress performs the necessary permission_callback checks. Consequently, unauthenticated attackers can successfully send malicious POST, PUT, or PATCH requests to the \u003ccode\u003e/wp/v2/global-styles\u003c/code\u003e route to inject arbitrary JavaScript. When a user subsequently views the affected page, the injected scripts execute in the context of the victim's session, potentially leading to administrative account takeover or session hijacking.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a WordPress user's session. This can lead to unauthorized actions performed as the user, administrative account compromise, or the redirection of site visitors to malicious external sites. The scope of impact is limited to users of WordPress sites running the vulnerable Extendify plugin version 3.1.6 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately update the Extendify WordPress plugin to a version patched against CVE-2026-85679.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to inspect and block POST, PUT, or PATCH requests to the \u003ccode\u003e/wp/v2/global-styles\u003c/code\u003e endpoint that contain anomalous characters or script tags in the \u003ccode\u003estyles.blocks\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for requests targeting \u003ccode\u003e/wp/v2/global-styles\u003c/code\u003e with unusual content types or payload structures.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-01T06:39:06Z","date_published":"2026-10-01T06:39:06Z","id":"https://feed.craftedsignal.io/briefs/2026-10-extendify-xss/","summary":"The Extendify plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) via the 'styles.blocks' parameter, allowing arbitrary script injection.","title":"Stored XSS Vulnerability in Extendify WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-extendify-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Extendify (\u003c= 3.1.6)","version":"https://jsonfeed.org/version/1.1"}