rootpwn

high · CVSS v3 7.2 · EPSS 0.00285

CVE-2026-97336

The CMB2 WordPress plugin up to 2.13.0 is vulnerable to stored XSS via the file_list field type. Unauthenticated attackers can inject script

Overview

The CMB2 WordPress plugin up to 2.13.0 is vulnerable to stored XSS via the file_list field type. Unauthenticated attackers can inject scripts that run for any user viewing the affected page. The flaw only triggers when a plugin or theme exposes a file_list field on a public form or user meta box.

Description

The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'file_list' Field Type in all versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when an integrating plugin or theme registers a file_list field on a publicly accessible front-end form or a user meta box, as CMB2 is a developer library and does not expose these fields by default.

Impact

Confidentiality: injected scripts can exfiltrate data or hijack sessions. Integrity: scripts can modify page content or redirect users. Availability: repeated XSS can degrade user experience. Defenders: site owners, developers, and administrators of WordPress sites using CMB2.

Remediation

Update CMB2 to the latest version (≥2.13.1) or apply the vendor patch. If an update is not possible, disable or remove any publicly exposed file_list fields, restrict form access to authenticated users, and implement a strict Content Security Policy that blocks inline scripts. Additionally, enable output escaping and input sanitization for custom fields.

Risk context

Severity is high with a CVSS v3 score of 7.2 and an EPSS of 0.00285, indicating a low but non-negligible likelihood of exploitation. Defenders should treat this as a moderate priority vulnerability that requires timely patching or mitigation.

Affected products

  • WordPress CMB2 plugin (≤2.13.0)

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
—
EPSS
0.00285

WordPress CMB2 XSS Stored XSS Front-end Plugin Security Vulnerability

← All CVEs