PatchSiren cyber security CVE debrief
CVE-2026-7509 helgatheviking CVE debrief
CVE-2026-7509 is a stored cross-site scripting vulnerability in the KIA Subtitle WordPress plugin for WordPress. According to the NVD description, the issue affects all versions up to and including 4.0.1 and can let authenticated users with Contributor-level access or higher inject script content through the plugin’s `the-subtitle` shortcode attributes.
- Vendor
- helgatheviking
- Product
- KIA Subtitle
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-22
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-22
- Advisory updated
- 2026-07-23
Who should care
WordPress site owners and administrators running KIA Subtitle 4.0.1 or earlier, especially sites that allow Contributor-level or higher user content creation.
Technical summary
The vulnerability is caused by insufficient input sanitization and output escaping for the shortcode’s `before` and `after` attributes. Because the issue is stored, malicious input can persist in content and execute when affected pages are viewed. The published CVSS vector indicates network access, low attack complexity, required low privileges, no user interaction, and a changed scope impact profile.
Defensive priority
Medium: this is a stored XSS issue in a WordPress plugin and should be prioritized for prompt patching, content review, and role-based access reduction.
Recommended defensive actions
- Update KIA Subtitle to a version newer than 4.0.1 as soon as a fixed release is available.
- Restrict Contributor-level and other content-creation permissions to trusted users only.
- Review posts and pages using the `the-subtitle` shortcode for unexpected `before` and `after` attribute values.
- Search for and remove any injected or suspicious script content in affected pages.
- Clear caches and re-publish cleaned content after remediation.
- Monitor for abnormal admin, editor, or front-end activity that could indicate stored XSS abuse.
Evidence notes
The NVD record describes the flaw as stored XSS in the KIA Subtitle plugin through the `the-subtitle` shortcode `before` and `after` attributes, affecting versions through 4.0.1. Wordfence-linked references point to plugin source lines in 4.0.1 and to 4.0.2/trunk, supporting the affected-version and remediation context without requiring exploit detail.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-7509 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-7509
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-7509 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-7509
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/kia-subtitle/tags/4.0.1/kia-subtitle.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/kia-subtitle/tags/4.0.1/kia-subtitle.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/kia-subtitle/tags/4.0.2/kia-subtitle.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/kia-subtitle/tags/4.0.2/kia-subtitle.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/kia-subtitle/trunk/kia-subtitle.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/kia-subtitle/trunk/kia-subtitle.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.