CVE Explorer
CVE-2026-7430
The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.19. This is due to insufficient output escaping of imported snippet content when rendering JavaScript variables in the post editor. Specifically, the `jqueryUiDialog()` method in `WPEditor.php` embeds snippet content directly into JavaScript string literals without escaping double quotes (the quote-escaping code on line 214 is commented out). When snippets are imported vi
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Post Snippets – Custom WordPress Code Snippets Customizer","vendor":"saadiqbal","versions":[{"lessThanOrEqual":"4.0.19","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:3c4bd86fb7d564a3a5b5c9c4da229cd187ee1a364e01783ffcf3b5eb38ce19e1 · sha256:c8c5a1f264203143… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:3c4bd86fb7d564a3a5b5c9c4da229cd187ee1a364e01783ffcf3b5eb38ce19e1 · sha256:c8c5a1f264203143… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3c4bd86fb7d564a3a5b5c9c4da229cd187ee1a364e01783ffcf3b5eb38ce19e1 · sha256:c8c5a1f264203143… · /containers/cna/problemTypes/0/descriptions/0
Source references
8 source assertions{"url":"https://plugins.trac.wordpress.org/browser/post-snippets/tags/4.0.19/src/PostSnippets/DBTable.php#L114"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3c4bd86fb7d564a3a5b5c9c4da229cd187ee1a364e01783ffcf3b5eb38ce19e1 · sha256:c8c5a1f264203143… · /containers/cna/references/3
{"url":"https://plugins.trac.wordpress.org/browser/post-snippets/tags/4.0.19/src/PostSnippets/WPEditor.php#L218"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3c4bd86fb7d564a3a5b5c9c4da229cd187ee1a364e01783ffcf3b5eb38ce19e1 · sha256:c8c5a1f264203143… · /containers/cna/references/1
{"url":"https://plugins.trac.wordpress.org/browser/post-snippets/tags/4.1.1/src/PostSnippets/WPEditor.php#L20"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3c4bd86fb7d564a3a5b5c9c4da229cd187ee1a364e01783ffcf3b5eb38ce19e1 · sha256:c8c5a1f264203143… · /containers/cna/references/5
{"url":"https://plugins.trac.wordpress.org/browser/post-snippets/tags/4.1.1/src/PostSnippets/WPEditor.php#L221"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3c4bd86fb7d564a3a5b5c9c4da229cd187ee1a364e01783ffcf3b5eb38ce19e1 · sha256:c8c5a1f264203143… · /containers/cna/references/6
{"url":"https://plugins.trac.wordpress.org/browser/post-snippets/tags/4.1.1/src/PostSnippets/WPEditor.php#L227"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3c4bd86fb7d564a3a5b5c9c4da229cd187ee1a364e01783ffcf3b5eb38ce19e1 · sha256:c8c5a1f264203143… · /containers/cna/references/7
{"url":"https://plugins.trac.wordpress.org/browser/post-snippets/trunk/src/PostSnippets/DBTable.php#L114"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3c4bd86fb7d564a3a5b5c9c4da229cd187ee1a364e01783ffcf3b5eb38ce19e1 · sha256:c8c5a1f264203143… · /containers/cna/references/4
{"url":"https://plugins.trac.wordpress.org/browser/post-snippets/trunk/src/PostSnippets/WPEditor.php#L218"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3c4bd86fb7d564a3a5b5c9c4da229cd187ee1a364e01783ffcf3b5eb38ce19e1 · sha256:c8c5a1f264203143… · /containers/cna/references/2
{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/59dc2448-491c-478f-a784-c727057b126b?source=cve"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3c4bd86fb7d564a3a5b5c9c4da229cd187ee1a364e01783ffcf3b5eb38ce19e1 · sha256:c8c5a1f264203143… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.