Security Advisory

CVE-2026-17010

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-10 06:00:13
Last updated 2026-08-10 19:15:47
Assigner WPScan
CVSS score 5.4
State PUBLISHED

Description

The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing users with contributor-level access and above to inject stored Cross-Site Scripting payloads that execute in the browser of a higher-privileged user who reviews the content.