<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Extendify (&lt;= 3.1.6) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/extendify--3.1.6/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 06:39:06 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/extendify--3.1.6/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS Vulnerability in Extendify WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-extendify-xss/</link><pubDate>Thu, 01 Oct 2026 06:39:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-extendify-xss/</guid><description>The Extendify plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) via the 'styles.blocks' parameter, allowing arbitrary script injection.</description><content:encoded><![CDATA[<p>The Extendify plugin for WordPress (versions 3.1.6 and earlier) contains a critical stored Cross-Site Scripting (XSS) vulnerability stemming from insufficient input sanitization and output escaping within the 'styles.blocks' block type key. The vulnerability is triggered because the <code>registerIncoming()</code> function is hooked to <code>rest_request_before_callbacks</code>. This causes the vulnerable code path to execute during REST API requests before WordPress performs the necessary permission_callback checks. Consequently, unauthenticated attackers can successfully send malicious POST, PUT, or PATCH requests to the <code>/wp/v2/global-styles</code> route to inject arbitrary JavaScript. When a user subsequently views the affected page, the injected scripts execute in the context of the victim's session, potentially leading to administrative account takeover or session hijacking.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a WordPress user's session. This can lead to unauthorized actions performed as the user, administrative account compromise, or the redirection of site visitors to malicious external sites. The scope of impact is limited to users of WordPress sites running the vulnerable Extendify plugin version 3.1.6 or earlier.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Immediately update the Extendify WordPress plugin to a version patched against CVE-2026-85679.</li>
<li>Implement a Web Application Firewall (WAF) rule to inspect and block POST, PUT, or PATCH requests to the <code>/wp/v2/global-styles</code> endpoint that contain anomalous characters or script tags in the <code>styles.blocks</code> parameter.</li>
<li>Review web server access logs for requests targeting <code>/wp/v2/global-styles</code> with unusual content types or payload structures.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>xss</category><category>wordpress</category><category>web-application-vulnerability</category></item></channel></rss>