PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8869 mutualfunddata CVE debrief

A stored cross-site scripting (XSS) vulnerability exists in the Mutual Funds Data WordPress plugin (versions up to and including 1.2.1). The flaw resides in the mfd_shortcode() function, where the 'title' shortcode attribute is concatenated directly into HTML output within a <caption> element without adequate input sanitization or output escaping. Authenticated attackers with Contributor-level access or higher can inject arbitrary web scripts that execute when users access affected pages. The vulnerability was disclosed on May 27, 2026, and carries a CVSS 3.1 score of 6.4 (Medium severity). No known exploitation in ransomware campaigns has been reported.

Vendor
mutualfunddata
Product
Mutual Funds Data
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-27
Original CVE updated
2026-05-27
Advisory published
2026-05-27
Advisory updated
2026-05-27

Who should care

WordPress site administrators using the Mutual Funds Data plugin; security teams managing WordPress installations with Contributor-level user access; web application security auditors reviewing WordPress plugin codebases.

Technical summary

The mfd_shortcode() function in mutual-funds-data.php fails to sanitize or escape the 'title' attribute before outputting it within a <caption> HTML element. This allows authenticated users with Contributor or higher privileges to inject JavaScript payloads through the shortcode's title parameter, which are then stored in post content and executed in victims' browsers when viewing the affected page. The vulnerability affects plugin versions up to and including 1.2.1.

Defensive priority

medium

Recommended defensive actions

  • Update the Mutual Funds Data WordPress plugin to a version beyond 1.2.1 if available, or remove the plugin if updates are not forthcoming.
  • Review existing posts and pages for suspicious shortcode usage, particularly [mutual_funds_data] shortcodes with malformed 'title' attributes containing script tags or event handlers.
  • Implement Content Security Policy (CSP) headers to mitigate impact of any stored XSS payloads that may already exist in the database.
  • Consider restricting Contributor-level user permissions or implementing additional content review workflows for users with post editing capabilities.
  • Monitor web access logs for unusual patterns that may indicate exploitation attempts targeting the mfd_shortcode() function.

Evidence notes

Vulnerability confirmed via Wordfence security advisory and WordPress plugin source code analysis. CWE-79 (Improper Neutralization of Input During Web Page Generation) identified as primary weakness. CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-8869 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-8869

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-8869 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8869

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.