high · CVSS v3 7.2 · EPSS 0.00236
CVE-2026-95817
The DoFollow Case by Case plugin for WordPress is vulnerable to stored XSS via comment content in all versions up to 3.6.0. Unauthenticated
Overview
The DoFollow Case by Case plugin for WordPress is vulnerable to stored XSS via comment content in all versions up to 3.6.0. Unauthenticated attackers can inject scripts that execute in the browsers of any visitor once a comment is approved. This flaw allows attackers to run arbitrary code on the client side, potentially compromising user sessions and data.
Description
The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation delays but does not prevent exploitation — once an administrator approves the visually innocuous comment, the stored payload executes in the browser of every subsequent visitor to the affected post.
Impact
Confidentiality: attackers can steal session cookies or other sensitive data from users. Integrity: injected scripts can modify page content or redirect users. Availability: repeated malicious comments may degrade user experience. The primary impact is on site visitors and administrators who approve comments.
Remediation
Update the plugin to version 3.6.1 or later where input sanitization and output escaping are fixed. If an update is not immediately possible, disable comment posting or enforce strict moderation and remove existing malicious comments. Additionally, implement a site-wide CSP that restricts script execution to trusted sources.
Risk context
Severity is high with a CVSS v3 score of 7.2, but the EPSS score of 0.00236 indicates a low likelihood of exploitation in the near term. Defenders should still prioritize patching due to the potential for widespread client-side compromise.
Affected products
- WordPress DoFollow Case by Case plugin
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- 0.00236