{
 "id": "WPSEC-2026-0746",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0746/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0746/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0746/index.md",
 "title": "Action Network <= 1.8.5 - Unauthenticated Reflected Cross-Site Scripting via Signup Widget Form Fields",
 "description": "The Action Network for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the signup widget's first name, last name and zip code fields in all versions up to, and including, 1.8.5, due to insufficient output escaping. The submitted values pass only through sanitize_text_field(), which keeps double quotes, and are printed unescaped into the value attributes of the re-rendered signup form. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into pages that show the signup widget. The scripts run when a user follows a crafted link or submits a crafted request. The attack needs the signup nonce, which is printed in the public form. The site must use the signup widget and have an Action Network API key configured.",
 "plugin": {
  "slug": "wp-action-network",
  "name": "Action Network",
  "full_name": "Organizers Embed – Action Network for WordPress",
  "wordpress_org": "https://wordpress.org/plugins/wp-action-network/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-action-network/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-action-network"
 },
 "type": "XSS",
 "cwe": [
  "CWE-79"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 6.1,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.9.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.9.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.9.0",
 "remediation": "Update to 1.9.0 or later.",
 "fix_released": "2026-10-09T01:50:05+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:54:02.588040+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0746/",
  "https://plugins.svn.wordpress.org/wp-action-network/tags/1.9.0/",
  "https://wordpress.org/plugins/wp-action-network/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-action-network",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-10"
 }
}