PatchSiren cyber security CVE debrief
CVE-2026-14835 SOGO CVE debrief
The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 is vulnerable to stored JavaScript execution due to lack of sanitization and escaping of custom header/footer script values. This vulnerability allows users with contributor-level access to store malicious JavaScript that executes in the browser of administrators and visitors. The CVE record was published on 2026-08-30T07:17:20.777Z and has not been modified since then. Affected product deployments should be reviewed and updated to prevent potential JavaScript execution.
- Vendor
- SOGO
- Product
- Add Script to Individual Pages Header Footer WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-30
- Original CVE updated
- 2026-08-30
- Advisory published
- 2026-08-30
- Advisory updated
- 2026-08-30
Who should care
Administrators and users with contributor-level access who use the SOGO Add Script to Individual Pages Header Footer WordPress plugin should review and update their installations to prevent potential JavaScript execution. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impact on their organization's WordPress deployments. Operators of WordPress platforms should also review their installations and ensure that they are not vulnerable to this issue. Security teams should monitor for potential JavaScript execution in the browser and review logs for exposed assets that need extra review. Vulnerability management teams should prioritize patching or mitigating this vulnerability based on the severity of the potential impact on their organization. Platform administrators should ensure that contributor-level access is properly restricted and that users with this access are aware of the potential risks associated with this vulnerability. Security teams should also review compensating controls for exposed systems while remediation is scheduled and verified. Asset inventory teams should verify that all affected systems are properly tracked and updated. Rollback and change window processes should be reviewed to ensure that patches can be applied quickly and efficiently. Source tracking and monitoring should be implemented to detect potential exploitation attempts. Monitoring and detection teams should review relevant logs and monitoring data to detect potential exploitation attempts. Compensating controls, such as web application firewalls, should be reviewed to ensure that they are properly configured to detect and prevent exploitation attempts. Asset inventory and vulnerability management teams should work together to ensure that all affected systems are properly tracked and updated. Security teams should also review and update their incident response plans to include procedures for responding to potential exploitation attempts. Finally, security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. This should be done in coordination with the IT
Technical summary
The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict them to users with the unfiltered_html capability. This allows users with contributor-level access and above to store JavaScript that executes in the browser of any administrator who reviews the post and of any visitor once the post is published. The vulnerability is a result of insufficient input validation and sanitization of user-supplied script values.
Defensive priority
Administrators and users with contributor-level access should review and update their WordPress installations to prevent potential JavaScript execution.
Recommended defensive actions
- Review and update the WordPress plugin to ensure proper sanitization and escaping of custom header/footer script values.
- Restrict access to users with unfiltered_html capability.
- Monitor for potential JavaScript execution in the browser.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape custom header/footer script values, allowing users with contributor-level access to store JavaScript that executes in the browser of administrators who review the post and visitors once the post is published. Evidence is limited; further verification is required.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-14835 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-14835
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-14835 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14835
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/f0b869b1-ef43-4540-9ca5-4440e763d307/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.