PatchSiren cyber security CVE debrief
CVE-2026-9677 Shariff for WordPress CVE debrief
The Shariff for WordPress plugin through 1.0.11 has a Stored Cross-Site Scripting vulnerability. The plugin does not sanitize or escape the shariff_infourl setting before outputting it in the frontend HTML via the generateshariff() function. This could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). The vulnerability has a CVSS score of 4.8 and a severity of MEDIUM. The CVE was published on 2026-06-27T06:16:34.783Z and modified on 2026-06-29T14:16:59.450Z.
- Vendor
- Shariff for WordPress
- Product
- Shariff for WordPress plugin
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-27
- Original CVE updated
- 2026-06-29
- Advisory published
- 2026-06-27
- Advisory updated
- 2026-06-29
Who should care
Administrators and users of the Shariff for WordPress plugin should be aware of this vulnerability and take necessary actions to mitigate it. This vulnerability can be exploited by high privilege users such as admin to perform Stored Cross-Site Scripting attacks. Users with the unfiltered_html capability disallowed (for example in multisite setup) are also affected.
Technical summary
The Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it in the frontend HTML via the generateshariff() function. This could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). The vulnerability has a CVSS score of 4.8 and a severity of MEDIUM. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N.
Defensive priority
High priority should be given to updating the Shariff for WordPress plugin to a version that fixes this vulnerability. Administrators should also ensure that the unfiltered_html capability is not allowed for users who should not have it.
Recommended defensive actions
- Update the Shariff for WordPress plugin to a version that fixes this vulnerability.
- Ensure that the unfiltered_html capability is not allowed for users who should not have it.
- Monitor the plugin and WordPress installation for any suspicious activity.
- Consider implementing additional security measures such as Content Security Policy (CSP) to mitigate XSS attacks.
- Review and update the plugin's configuration to prevent exploitation.
Evidence notes
The CVE-2026-9677 vulnerability was reported by Wpscan. The vulnerability is a Stored Cross-Site Scripting vulnerability in the Shariff for WordPress plugin through 1.0.11. The CVE was published on 2026-06-27T06:16:34.783Z and modified on 2026-06-29T14:16:59.450Z. The CVSS score is 4.8 and the severity is MEDIUM.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-9677 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-9677
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-9677 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9677
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/c40298d0-42c2-406c-817a-9bbf246bbeea/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.