Vulnerabilities / Action Network / WPSEC-2026-0746

Action Network <= 1.8.5 - Unauthenticated Reflected Cross-Site Scripting via Signup Widget Form Fields

Medium 6.1 CWE-79Fixed in 1.9.0
ID
WPSEC-2026-0746
Plugin
Organizers Embed – Action Network for WordPress (wp-action-network)
Affected
all versions before 1.9.0
Remediation
Update to 1.9.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-10
Attack surface
Action Network on WPSec AttackSurface
Fix released
Published

Description

The Action Network for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the signup widget's first name, last name and zip code fields in all versions up to, and including, 1.8.5, due to insufficient output escaping. The submitted values pass only through sanitize_text_field(), which keeps double quotes, and are printed unescaped into the value attributes of the re-rendered signup form. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into pages that show the signup widget. The scripts run when a user follows a crafted link or submits a crafted request. The attack needs the signup nonce, which is printed in the public form. The site must use the signup widget and have an Action Network API key configured.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0