PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-88905 KeyWord Collector CVE debrief

The KeyWord Collector WordPress plugin through 1.4 does not have any authorisation or nonce check when saving its settings, and does not escape them before output, allowing unauthenticated attackers to store malicious JavaScript that executes when an administrator opens the KeyWord Collector WordPress plugin through 1.4's settings page or when a visitor loads a page displaying its output.

Vendor
KeyWord Collector
Product
WordPress plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for WordPress installations, particularly those using the KeyWord Collector plugin, should assess exposure and prioritize verification and potential remediation.

Why it matters

The KeyWord Collector WordPress plugin vulnerability allows unauthenticated attackers to store malicious JavaScript, potentially leading to security issues. Defenders should prioritize verifying exposure and assessing the security of their WordPress installations.

  • Potential execution of malicious JavaScript on the settings page or when a visitor loads a page displaying the output
  • Possible unauthorized storage of malicious JavaScript
  • Required verification of WordPress installation security and plugin version

Technical summary

The KeyWord Collector WordPress plugin through 1.4 does not have any authorisation or nonce check when saving its settings, and does not escape them before output, allowing unauthenticated attackers to store malicious JavaScript that executes when an administrator opens the KeyWord Collector WordPress plugin through 1.4's settings page or when a visitor loads a page displaying its output. Defenders should prioritize verifying exposure of the KeyWord Collector WordPress plugin version 1.4 or earlier and assess the security of their WordPress installations.

Defensive priority

Defenders should prioritize verifying exposure of the KeyWord Collector WordPress plugin version 1.4 or earlier and assess the security of their WordPress installations.

Recommended defensive actions

  • Verify the version of the KeyWord Collector WordPress plugin and upgrade to a patched version if necessary
  • Assess the security of WordPress installations and ensure proper authorization and nonce checks are in place
  • Monitor for potential malicious JavaScript execution
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Further verification is required to determine the affected versions and potential impact. Defenders should verify the security of WordPress installations using the KeyWord Collector plugin version 1.4 or earlier and assess potential exposure to malicious JavaScript storage and execution.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-88905 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-88905

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-88905 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-88905

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.