Action Network <= 1.8.5 - Unauthenticated Reflected Cross-Site Scripting via Signup Widget Form Fields
- ID
- WPSEC-2026-0746
- Plugin
- Organizers Embed – Action Network for WordPress (wp-action-network)
- Affected
- all versions before 1.9.0
- Remediation
- Update to 1.9.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-10
- Attack surface
- Action Network on WPSec AttackSurface
- Fix released
- Published
Description
The Action Network for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the signup widget's first name, last name and zip code fields in all versions up to, and including, 1.8.5, due to insufficient output escaping. The submitted values pass only through sanitize_text_field(), which keeps double quotes, and are printed unescaped into the value attributes of the re-rendered signup form. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into pages that show the signup widget. The scripts run when a user follows a crafted link or submits a crafted request. The attack needs the signup nonce, which is printed in the public form. The site must use the signup widget and have an Action Network API key configured.
References
- https://wpsec.com/vuln/WPSEC-2026-0746/
- https://plugins.svn.wordpress.org/wp-action-network/tags/1.9.0/
- https://wordpress.org/plugins/wp-action-network/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS