PatchSiren cyber security CVE debrief
CVE-2026-6397 cvmh CVE debrief
The Sticky plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability in versions up to and including 2.5.6. The flaw exists in the `cvmh_sticky_front_render()` function, where the `readmoretext` attribute of the `cvmh-sticky` shortcode is passed through `apply_filters()` and directly concatenated into HTML output without escaping functions such as `esc_html()`. This allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts that execute when users access pages containing the malicious shortcode. The vulnerability was published on 2026-05-20 and carries a CVSS 3.1 score of 6.4 (Medium severity).
- Vendor
- cvmh
- Product
- Sticky
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-20
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-20
- Advisory updated
- 2026-07-24
Who should care
WordPress site administrators using the Sticky plugin; security teams managing content management system (CMS) deployments; developers maintaining WordPress plugins with custom shortcode implementations
Technical summary
The vulnerability stems from insufficient input sanitization and output escaping in the Sticky plugin's shortcode handler. Specifically, the `readmoretext` attribute value flows through `apply_filters()` and is directly embedded into HTML output without escaping. This pattern violates WordPress security best practices for shortcode attribute handling. The attack requires authenticated access at Contributor level or above, limiting exposure to sites with untrusted content contributors. The CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N reflects network attack vector, low attack complexity, low privileges required, no user interaction, changed scope, and low impacts to confidentiality and integrity.
Defensive priority
medium
Recommended defensive actions
- Update the Sticky WordPress plugin to a version newer than 2.5.6 if available
- Review existing posts and pages for unauthorized use of the cvmh-sticky shortcode with suspicious readmoretext attributes
- Implement least-privilege access controls for Contributor and Author roles pending patch availability
- Consider deploying a Web Application Firewall (WAF) rule to filter malicious shortcode payloads as a temporary mitigation
- Audit plugin code for similar unescaped output patterns in custom shortcode implementations
Evidence notes
Vulnerability confirmed via WordPress plugin repository source code analysis. The vulnerable code path is present in both the tagged 2.5.6 release and trunk versions. Wordfence assigned CVE identifier and provided technical analysis.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-6397 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-6397
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-6397 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6397
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/sticky/tags/2.5.6/includes/functions.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/sticky/tags/2.5.6/includes/shortcode.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/sticky/trunk/includes/functions.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/sticky/trunk/includes/shortcode.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.