# Action Network <= 1.8.5 - Unauthenticated Reflected Cross-Site Scripting via Signup Widget Form Fields

- **ID:** WPSEC-2026-0746
- **Plugin:** Organizers Embed – Action Network for WordPress (`wp-action-network`), https://wordpress.org/plugins/wp-action-network/
- **Affected versions:** all versions before 1.9.0
- **Fixed in:** 1.9.0 (Update to 1.9.0 or later.)
- **Severity:** Medium 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-action-network
- **Fix released:** 2026-10-09
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0746/

## Description

The Action Network for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the signup widget's first name, last name and zip code fields in all versions up to, and including, 1.8.5, due to insufficient output escaping. The submitted values pass only through sanitize_text_field(), which keeps double quotes, and are printed unescaped into the value attributes of the re-rendered signup form. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into pages that show the signup widget. The scripts run when a user follows a crafted link or submits a crafted request. The attack needs the signup nonce, which is printed in the public form. The site must use the signup widget and have an Action Network API key configured.

## References

- https://wpsec.com/vuln/WPSEC-2026-0746/
- https://plugins.svn.wordpress.org/wp-action-network/tags/1.9.0/
- https://wordpress.org/plugins/wp-action-network/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0746/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
