CVE-2026-85129
Hoo Companion 1.0.2 - Unauthenticated Stored XSS via Theme Settings Import
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web scripts which will execute for anyone viewing the site, including administrators. The same request destroys the site's existing theme settings.
| Vendor | unknown |
| Product | hoo companion |
| Published | Sep 13, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown hoo companion
Be the first to know when new high vulnerabilities affecting unknown hoo companion are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Unknown / Hoo Companion
1.0.2 โค 1.0.2
References
Credits
Enrico Marcolini (Dottor Marc) Claudio Marchesini (Dottor Marc) WPScan